CVE-2025-27054
Published Oct 9, 2025Memory corruption while processing a malformed license file during reboot.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
102 CVEs tagged to qualcomm / 315_5g_iot_modem — 9 Critical, 87 High, 6 Medium, 0 Low, 0 Unrated.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while performing private key encryption in trusted application.
Transient DOS while processing an ANQP message.
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Information disclosure while processing the hash segment in an MBN file.
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
Memory corruption while processing video packets received from video firmware.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Transient DOS while loading the TA ELF file.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
Memory corruption when there is failed unmap operation in GPU.
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.