Vulnerability Description
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Sm6225P Firmware | - |
| Qualcomm | Sm6225P | - |
| Qualcomm | Sm6450P Firmware | - |
| Qualcomm | Sm6450P | - |
| Qualcomm | Sm6475P Firmware | - |
| Qualcomm | Sm6475P | - |
| Qualcomm | Sm6475Q Firmware | - |
| Qualcomm | Sm6475Q | - |
| Qualcomm | Sm6850 Firmware | - |
| Qualcomm | Sm6850 | - |
| Qualcomm | Sm7435 Firmware | - |
| Qualcomm | Sm7435 | - |
| Qualcomm | Sm7435P Firmware | - |
| Qualcomm | Sm7435P | - |
| Qualcomm | Sm7525 Firmware | - |
| Qualcomm | Sm7525 | - |
| Qualcomm | Sm7550 Firmware | - |
| Qualcomm | Sm7550 | - |
| Qualcomm | Sm7550P Firmware | - |
| Qualcomm | Sm7550P | - |
Related Weaknesses (CWE)
References
- https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bPatchVendor Advisory
FAQ
What is CVE-2026-25292?
CVE-2026-25292 is a vulnerability with a CVSS score of 7.6 (HIGH). Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
How severe is CVE-2026-25292?
CVE-2026-25292 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25292?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Sm6225P Firmware, Qualcomm Sm6225P, Qualcomm Sm6450P Firmware, Qualcomm Sm6450P, Qualcomm Sm6475P Firmware.