CVE-2026-24091
Published Jun 1, 2026Memory corruption while processing fastboot commands with improperly formatted input.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
90 CVEs tagged to qualcomm / c-v2x_9150 — 6 Critical, 55 High, 29 Medium, 0 Low, 0 Unrated.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
information disclosure while invoking calibration data from user space to update firmware size.
Memory corruption while performing private key encryption in trusted application.
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing video packets received from video firmware.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Memory corruption while processing IOCTL calls to add route entry in the HW.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption while calling the NPU driver APIs concurrently.
Information disclosure while deriving keys for a session for any Widevine use case.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure while processing IO control commands.
Information disclosure during audio playback.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or inv…
Memory corruption while processing concurrent IOCTL calls.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.