CVE-2025-59617
MEDIUMDescription
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Is your site exposed to CVE-2025-59617?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | fastconnect_6700_firmware |
| qualcomm | fastconnect_6700 |
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | molokai_firmware |
| qualcomm | molokai |
| qualcomm | orne_firmware |
| qualcomm | orne |
| qualcomm | pandeiro_firmware |
| qualcomm | pandeiro |
| qualcomm | qcm5430_firmware |
| qualcomm | qcm5430 |
| qualcomm | qcm6490_firmware |
| qualcomm | qcm6490 |
| qualcomm | qmp1000_firmware |
| qualcomm | qmp1000 |
| qualcomm | qmp2001_firmware |
| qualcomm | qmp2001 |
| qualcomm | video_collaboration_vc3_platform_firmware |
| qualcomm | video_collaboration_vc3_platform |
| qualcomm | sc8380xp_firmware |
| qualcomm | sc8380xp |
| qualcomm | sd865_5g_firmware |
| qualcomm | sd865_5g |
| qualcomm | sm6850_firmware |
| qualcomm | sm6850 |
| qualcomm | sm8845p_firmware |
| qualcomm | sm8845p |
| qualcomm | snapdragon_460_mobile_platform_firmware |
| qualcomm | snapdragon_460_mobile_platform |
| qualcomm | snapdragon_662_mobile_platform_firmware |
| qualcomm | snapdragon_662_mobile_platform |
| qualcomm | snapdragon_8_elite_gen_5_firmware |
| qualcomm | snapdragon_8_elite_gen_5 |
| qualcomm | snapdragon_ar1_gen_1_platform_firmware |
| qualcomm | snapdragon_ar1_gen_1_platform |
| qualcomm | snapdragon_xr2_5g_platform_firmware |
| qualcomm | snapdragon_xr2_5g_platform |
| qualcomm | snapdragon_xr2\+_gen_1_platform_firmware |
| qualcomm | snapdragon_xr2\+_gen_1_platform |
| qualcomm | sxr2230p_firmware |
| qualcomm | sxr2230p |
| qualcomm | sxr2250p_firmware |
| qualcomm | sxr2250p |
| qualcomm | wcd9370_firmware |
| qualcomm | wcd9370 |
| qualcomm | wcd9375_firmware |
| qualcomm | wcd9375 |
| qualcomm | wcd9378_firmware |
| qualcomm | wcd9378 |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcd9395_firmware |
| qualcomm | wcd9395 |
| qualcomm | wcn3950_firmware |
| qualcomm | wcn3950 |
| qualcomm | wcn3988_firmware |
| qualcomm | wcn3988 |
| qualcomm | wcn6450_firmware |
| qualcomm | wcn6450 |
| qualcomm | wcn7760_firmware |
| qualcomm | wcn7760 |
| qualcomm | wcn7860_firmware |
| qualcomm | wcn7860 |
| qualcomm | wcn7861_firmware |
| qualcomm | wcn7861 |
| qualcomm | wcn7880_firmware |
| qualcomm | wcn7880 |
| qualcomm | wcn7881_firmware |
| qualcomm | wcn7881 |
| qualcomm | wsa8810_firmware |
| qualcomm | wsa8810 |
| qualcomm | wsa8815_firmware |
| qualcomm | wsa8815 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
| qualcomm | wsa8850_firmware |
| qualcomm | wsa8850 |
| qualcomm | wsa8850w_firmware |
| qualcomm | wsa8850w |
| qualcomm | wsa8855c_firmware |
| qualcomm | wsa8855c |
References
Frequently Asked Questions
What is CVE-2025-59617? +
How severe is CVE-2025-59617? +
What products are affected by CVE-2025-59617? +
How do I check if I'm vulnerable to CVE-2025-59617? +
Related Vulnerabilities
Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the …
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the …
rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice …
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder …
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue …
There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an …