CVE-2026-25281: CWE-770: Allocation of Resources Without Limits or Throttling in Qualcomm, Inc. Snapdragon
CVE-2026-25281 is a high-severity vulnerability in Qualcomm Snapdragon devices WSA8840 and WSA8845. It involves allocation of resources without limits or throttling, leading to a transient denial of service (DoS) when processing large or numerous request buffers without sufficient memory allocation validation.
AI Analysis
Technical Summary
This vulnerability, classified as CWE-770, occurs in Qualcomm Snapdragon devices WSA8840 and WSA8845. It allows an attacker to cause a transient denial of service by sending large or numerous request buffers that the system processes without adequate memory allocation validation or throttling. The flaw results in resource exhaustion, impacting availability but not confidentiality or integrity. The CVSS v3.1 score is 7.4, reflecting a high impact on availability with network attack vector, low attack complexity, no privileges required, no user interaction, and scope change.
Potential Impact
Successful exploitation causes a transient denial of service condition, disrupting normal device operation by exhausting memory resources. There is no impact on confidentiality or integrity. No known exploits are reported in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check Qualcomm's vendor advisory for current remediation guidance. Until a fix is available, limit exposure by controlling access to affected devices and monitoring for abnormal request patterns that could trigger resource exhaustion.
CVE-2026-25281: CWE-770: Allocation of Resources Without Limits or Throttling in Qualcomm, Inc. Snapdragon
Description
CVE-2026-25281 is a high-severity vulnerability in Qualcomm Snapdragon devices WSA8840 and WSA8845. It involves allocation of resources without limits or throttling, leading to a transient denial of service (DoS) when processing large or numerous request buffers without sufficient memory allocation validation.
CVSS v3.1
Score 7.4high
Affected software
Qualcomm, Inc.
Snapdragon
pkg:github/qualcomm/snapdragonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, classified as CWE-770, occurs in Qualcomm Snapdragon devices WSA8840 and WSA8845. It allows an attacker to cause a transient denial of service by sending large or numerous request buffers that the system processes without adequate memory allocation validation or throttling. The flaw results in resource exhaustion, impacting availability but not confidentiality or integrity. The CVSS v3.1 score is 7.4, reflecting a high impact on availability with network attack vector, low attack complexity, no privileges required, no user interaction, and scope change.
Potential Impact
Successful exploitation causes a transient denial of service condition, disrupting normal device operation by exhausting memory resources. There is no impact on confidentiality or integrity. No known exploits are reported in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check Qualcomm's vendor advisory for current remediation guidance. Until a fix is available, limit exposure by controlling access to affected devices and monitoring for abnormal request patterns that could trigger resource exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- qualcomm
- Date Reserved
- 2026-02-02T04:19:00.941Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aab6d4c55bf5e2cf5bd417f
Added to database: 09/17/2026, 04:32:12 UTC
Last enriched: 09/17/2026, 04:47:12 UTC
Last updated: 09/17/2026, 05:38:15 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.