{"id":"CVE-2026-25278","title":"Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.","summary":"Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-367"],"vendor":"qualcomm","product":"lemans_au_lgit_firmware","affected":["lemans_au_lgit_firmware","lemansau_firmware","qam8255p_firmware","qam8295p_firmware","qam8620p_firmware","qamsrv1h_firmware","qamsrv1m_firmware","qca6574au_firmware","qca6595_firmware","qca6595au_firmware","qca6688aq_firmware","qca6696_firmware","qca6698aq_firmware","qca6797aq_firmware","qca8695au_firmware","sa6155p_firmware","sa7255p_firmware","sa7775p_firmware","sa8155p_firmware","sa8195p_firmware","sa8255p_firmware","sa8295p_firmware","sa8540p_firmware","sa8620p_firmware","sa8770p_firmware","sa9000p_firmware","srv1h_firmware","srv1l_firmware","srv1m_firmware"],"published":"2026-09-17","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:21:05.403","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-25278","references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html","label":"product-security@qualcomm.com"}],"tags":["nvd","cve.org"],"epss":0.00052,"epssPercentile":0.00002,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T14:37:08.902332Z"},"ingestedAt":"2026-09-17T05:11:38.054Z","slug":"CVE-2026-25278","body":"## Overview\n\nMemory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.\n\n## Affected\n\n- `lemans_au_lgit_firmware`\n- `lemansau_firmware`\n- `qam8255p_firmware`\n- `qam8295p_firmware`\n- `qam8620p_firmware`\n- `qamsrv1h_firmware`\n- `qamsrv1m_firmware`\n- `qca6574au_firmware`\n- `qca6595_firmware`\n- `qca6595au_firmware`\n- `qca6688aq_firmware`\n- `qca6696_firmware`\n- `qca6698aq_firmware`\n- `qca6797aq_firmware`\n- `qca8695au_firmware`\n- `sa6155p_firmware`\n- `sa7255p_firmware`\n- `sa7775p_firmware`\n- `sa8155p_firmware`\n- `sa8195p_firmware`\n- `sa8255p_firmware`\n- `sa8295p_firmware`\n- `sa8540p_firmware`\n- `sa8620p_firmware`\n- `sa8770p_firmware`\n- `sa9000p_firmware`\n- `srv1h_firmware`\n- `srv1l_firmware`\n- `srv1m_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}