CVE-2026-25271
Published Jul 6, 2026Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
27 CVEs tagged to qualcomm / cologne — 0 Critical, 22 High, 5 Medium, 0 Low, 0 Unrated.
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
Memory corruption while processing multiple IOCTL command for escape operations.
Memory corruption while processing IOCTL calls for escape operations.
Memory Corruption when processing fastboot commands to set display mode.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory corruption while processing fastboot commands with invalid input.
Memory corruption while processing fastboot OEM commands.
Memory Corruption when sending random number generator command with insufficient output buffer size.
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Memory corruption in windows drivers while sending incorrect trusted application request
Memory corruption in diagnostic services due to absence of input validation
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
Memory corruption while processing IOCTL command when device is in power-save state.
Memory Corruption when handling power management requests with improperly sized input/output buffers.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory Corruption when processing invalid user address with nonstandard buffer address.
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.