CVE-2026-24091
Published Jun 1, 2026Memory corruption while processing fastboot commands with improperly formatted input.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
286 CVEs tagged to qualcomm / csrb31024 — 44 Critical, 197 High, 45 Medium, 0 Low, 0 Unrated.
Memory corruption while processing fastboot commands with improperly formatted input.
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
Memory corruption while handling file descriptor during listener registration/de-registration.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Transient DOS while loading the TA ELF file.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
Memory corruption when there is failed unmap operation in GPU.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption in SPS Application while requesting for public key in sorter TA.
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
Memory corruption in Core Services while executing the command for removing a single event listener.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of…
Memory corruption in Core while processing control functions.
Memory corruption in Audio when memory map command is executed consecutively in ADSP.