Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-47374


Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.5, requiring local system access to exploit but requires specific conditions to be met without requiring user interaction requiring only low-level privileges . The vulnerability impacts limited data confidentiality, integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 60 products from qualcomm, from qualcomm, from qualcomm and 57 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2026, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2026-04-06T16:16:27.177

Last Modified

2026-04-08T21:09:54.443

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm fastconnect_6900_firmware - Yes
Hardware qualcomm fastconnect_6900 - No
Operating System qualcomm fastconnect_7800_firmware - Yes
Hardware qualcomm fastconnect_7800 - No
Operating System qualcomm pandeiro_firmware - Yes
Hardware qualcomm pandeiro - No
Operating System qualcomm qln1083bd_firmware - Yes
Hardware qualcomm qln1083bd - No
Operating System qualcomm qln1086bd_firmware - Yes
Hardware qualcomm qln1086bd - No
Operating System qualcomm qpa1083bd_firmware - Yes
Hardware qualcomm qpa1083bd - No
Operating System qualcomm qpa1086bd_firmware - Yes
Hardware qualcomm qpa1086bd - No
Operating System qualcomm qxm1083_firmware - Yes
Hardware qualcomm qxm1083 - No
Operating System qualcomm qxm1086_firmware - Yes
Hardware qualcomm qxm1086 - No
Operating System qualcomm qxm1093_firmware - Yes
Hardware qualcomm qxm1093 - No
Operating System qualcomm qxm1094_firmware - Yes
Hardware qualcomm qxm1094 - No
Operating System qualcomm qxm1095_firmware - Yes
Hardware qualcomm qxm1095 - No
Operating System qualcomm qxm1096_firmware - Yes
Hardware qualcomm qxm1096 - No
Operating System qualcomm sar1165p_firmware - Yes
Hardware qualcomm sar1165p - No
Operating System qualcomm sar2130p_firmware - Yes
Hardware qualcomm sar2130p - No
Operating System qualcomm snapdragon_ar1_gen_1_platform_firmware - Yes
Hardware qualcomm snapdragon_ar1_gen_1_platform - No
Operating System qualcomm snapdragon_ar1\+_gen_1_platform_firmware - Yes
Hardware qualcomm snapdragon_ar1\+_gen_1_platform - No
Operating System qualcomm sxr2230p_firmware - Yes
Hardware qualcomm sxr2230p - No
Operating System qualcomm sxr2250p_firmware - Yes
Hardware qualcomm sxr2250p - No
Operating System qualcomm sxr2330p_firmware - Yes
Hardware qualcomm sxr2330p - No
Operating System qualcomm sxr2350p_firmware - Yes
Hardware qualcomm sxr2350p - No
Operating System qualcomm wcd9380_firmware - Yes
Hardware qualcomm wcd9380 - No
Operating System qualcomm wcd9385_firmware - Yes
Hardware qualcomm wcd9385 - No
Operating System qualcomm wcn7860_firmware - Yes
Hardware qualcomm wcn7860 - No
Operating System qualcomm wcn7861_firmware - Yes
Hardware qualcomm wcn7861 - No
Operating System qualcomm wsa8830_firmware - Yes
Hardware qualcomm wsa8830 - No
Operating System qualcomm wsa8832_firmware - Yes
Hardware qualcomm wsa8832 - No
Operating System qualcomm wsa8835_firmware - Yes
Hardware qualcomm wsa8835 - No
Operating System qualcomm xrv7209_firmware - Yes
Hardware qualcomm xrv7209 - No
Operating System qualcomm xrv9209_firmware - Yes
Hardware qualcomm xrv9209 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For qualcomm's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.