Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210437
https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html