CVE-2025-27053
Published Oct 9, 2025Memory corruption during PlayReady APP usecase while processing TA commands.
Vendor/product archive
533 CVEs tagged to qualcomm / mdm9650_firmware — 189 Critical, 266 High, 78 Medium, 0 Low, 0 Unrated.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption during concurrent access to server info object due to unprotected critical field.
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
Certain unprivileged processes are able to perform IOCTL calls.
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
Memory corruption in Audio while processing IIR config data from AFE calibration block.
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
Information disclosure in Audio while accessing AVCS services from ADSP payload.
Transient DOS in Audio when invoking callback function of ASM driver.
Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.
Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.
Memory corruption while invoking callback function of AFE from ADSP.
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Memory corruption in Graphics while processing user packets for command submission.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Memoru corruption in Audio when ADSP sends input during record use case.
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
Memory corruption in WLAN due to use after free
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
Memory corruption due to stack-based buffer overflow in Core