CVE-2026-25288
Published Aug 4, 2026Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
13 CVEs tagged to qualcomm / pandeiro_firmware — 0 Critical, 7 High, 6 Medium, 0 Low, 0 Unrated.
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
Memory corruption while using Strongbox due to buffer overflow.
Memory corruption while using Strongbox due to missing bounds check.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
Cryptographic issue while copying data to a destination buffer without validating its size.
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.