VYPR
Unrated severityOSV Advisory· Published Dec 10, 2025· Updated Dec 23, 2025

CVE-2025-24857

CVE-2025-24857

Description

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

Affected products

4
  • U Boot/U BootOSV2 versions
    LABEL_2002_11_05_0120, LABEL_2002_11_05_1735, LABEL_2002_11_10_2310, …+ 1 more
    • (no CPE)range: LABEL_2002_11_05_0120, LABEL_2002_11_05_1735, LABEL_2002_11_10_2310, …
    • (no CPE)range: <2017.11
  • Qualcomm/IPQ4019llm-create
  • Qualcomm/IPQ8074llm-create

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.