CVE-2025-21433
Published Jul 8, 2025Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
115 CVEs tagged to qualcomm / apq8037 — 34 Critical, 69 High, 12 Medium, 0 Low, 0 Unrated.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while processing API calls to NPU with invalid input.
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption in SPS Application while requesting for public key in sorter TA.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in HLOS while running playready use-case.
Memory corruption while using the UIM diag command to get the operators name.
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.