CVE-2025-21488

8.2

Qualcomm · Snapdragon FastConnect and MSM8996AU

A buffer over-read vulnerability in Qualcomm Snapdragon hardware allows for information disclosure when processing RTP packet headers with the padding bit set.

Executive summary

A high-severity buffer over-read vulnerability in specific Qualcomm Snapdragon components could allow unauthenticated attackers to disclose sensitive information.

Vulnerability

This is a buffer over-read vulnerability (CWE-126) triggered during the decoding of RTP packet headers when the padding bit is set. The vulnerability is network-accessible and requires no authentication or user interaction to trigger.

Business impact

Successful exploitation of this flaw allows an attacker to read out-of-bounds memory, potentially leading to the exposure of sensitive data processed by the affected hardware. With a CVSS score of 8.2, this vulnerability represents a significant risk, as it is easily exploitable over the network without requiring any privileges, potentially leading to unauthorized access to system information or memory contents.

Remediation

Immediate Action: Monitor the Qualcomm security portal for the release of firmware updates specific to the affected FastConnect and MSM modules and apply them as soon as they are made available.

Proactive Monitoring: Security teams should review network traffic logs for malformed RTP packets or unusual traffic patterns directed at devices utilizing the affected Qualcomm chipsets.

Compensating Controls: While direct firmware patching is preferred, implementing network-level filtering to drop suspicious or malformed RTP traffic may reduce the risk of exploitation.

Exploitation status

Public Exploit Available: No (exploit_available is false/unknown).

Analyst recommendation

The vulnerability poses a substantial risk due to its ability to be triggered remotely without authentication. Organizations using devices equipped with the affected Qualcomm Snapdragon hardware must prioritize the application of vendor-supplied firmware updates as soon as they are released. Until patches are applied, restrict network access to vulnerable devices to mitigate the risk of remote exploitation.

More Qualcomm CVEs

Sources