CVE-2026-24088
Published Jun 1, 2026Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
226 CVEs tagged to qualcomm / csr8811 — 28 Critical, 167 High, 31 Medium, 0 Low, 0 Unrated.
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Information disclosure while processing a firmware event.
Memory corruption while processing a GP command response.
Information disclosure may occur while processing the hypervisor log.
Transient DOS while handling command data during power control processing.
Transient DOS while handling beacon frames with invalid IE header length.
Memory corruption while processing manipulated payload in video firmware.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing the EHT operation IE in the received beacon frame.
Transient DOS may occur while parsing extended IE in beacon.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
Memory corruption while parsing the ML IE due to invalid frame content.
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
Transient DOS while parsing the received TID-to-link mapping action frame.
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.