CVE-2025-27064
Published Nov 4, 2025Information disclosure while registering commands from clients with diag through diagHal.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
27 CVEs tagged to qualcomm / immersive_home_326_platform_firmware — 1 Critical, 19 High, 7 Medium, 0 Low, 0 Unrated.
Information disclosure while registering commands from clients with diag through diagHal.
Transient DOS while processing power control requests with invalid antenna or stream values.
Transient DOS while processing a frame with malformed shared-key descriptor.
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
Transient DOS while parsing the received TID-to-link mapping action frame.
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.
Information disclosure while parsing sub-IE length during new IE generation.
Information disclosure while handling SA query action frame.
INformation disclosure while handling Multi-link IE in beacon frame.
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Transient DOS while processing 11AZ RTT management action frame received through OTA.
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
Transient DOS in WLAN Firmware while processing a FTMR frame.
Memory corruption in Kernel while parsing metadata.
Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.