CVE-2025-47386
Published Mar 2, 2026Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Vendor/product archive
58 CVEs tagged to qualcomm / flight_rb5_5g_platform — 3 Critical, 51 High, 4 Medium, 0 Low, 0 Unrated.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling IOCTL calls to set mode.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling by…
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption while allocating memory in HGSL driver.
Memory corruption while processing IOCTL call to set metainfo.
Transient DOS while processing TID-to-link mapping IE elements.
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption while handling user packets during VBO bind operation.
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.