---
id: CVE-2026-25272
title: >-
  Memory Corruption when processing camera CRE driver operations with improper
  handling of buffer limits during hardware update preparation.
summary: >-
  Memory Corruption when processing camera CRE driver operations with improper
  handling of buffer limits during hardware update preparation.
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: 'Qualcomm, Inc.'
product: Snapdragon
affected:
  - Snapdragon Cologne
  - Snapdragon CQ7790
  - Snapdragon CQ8725S
  - Snapdragon CQ8750M
  - Snapdragon FastConnect 6700
  - Snapdragon FastConnect 6900
  - Snapdragon FastConnect 7800
  - Snapdragon IQ10 Series
  - Snapdragon IQ6 Series Platform
  - Snapdragon IQ8 Series Platform
  - Snapdragon IQ9 Series Platform
  - Snapdragon LeMans_AU_LGIT
  - Snapdragon LeMansAU
  - Snapdragon MBM415
  - Snapdragon MBM715
  - Snapdragon Milos
  - Snapdragon Monaco_IOT
  - Snapdragon Orne
  - Snapdragon Palawan25
  - Snapdragon Pandeiro
  - Snapdragon QAM8255P
  - Snapdragon QAMSRV1H
  - Snapdragon QAMSRV1M
  - Snapdragon QCA6391
  - Snapdragon QCA6595
  - Snapdragon QCA6595AU
  - Snapdragon QCA6678AQ
  - Snapdragon QCA6698AQ
  - Snapdragon QCA6698AU
  - Snapdragon QCA6797AQ
  - Snapdragon QCA8695AU
  - Snapdragon QCM5430
  - Snapdragon QCM6490
  - Snapdragon QCM8550
  - Snapdragon QCM8838
  - Snapdragon QCN9011
  - Snapdragon QCN9012
  - Snapdragon QCN9274
  - Snapdragon QCS8550
  - Snapdragon QLN1083BD
  - Snapdragon QLN1086BD
  - Snapdragon QMP1000
  - Snapdragon QPA1083BD
  - Snapdragon QPA1086BD
  - Snapdragon Qualcomm Dragonwing Q-6690
  - Snapdragon Qualcomm Dragonwing Q-7790
  - Snapdragon Qualcomm Dragonwing Q-8845
  - Snapdragon Qualcomm Dragonwing QCM4490
  - Snapdragon Qualcomm Video Collaboration VC3 Platform
  - Snapdragon QXM1083
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:57.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25272'
references:
  - url: >-
      https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2026-bulletin.html
    label: product-security@qualcomm.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T07:49:23.039Z'
---

## Overview

Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
