CVE-2026-25268
Published Jul 6, 2026Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
157 CVEs tagged to qualcomm / qca6174a — 32 Critical, 99 High, 26 Medium, 0 Low, 0 Unrated.
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Transient DOS while processing video packets received from video firmware.
Memory corruption while selecting the PLMN from SOR failed list.
Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
Memory corruption while IOCTL call is invoked from user-space to read board data.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Memory corruption while invoking IOCTL map buffer request from userspace.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Memory corruption may occur while accessing a variable during extended back to back tests.
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Information disclosure while processing information on firmware image during core initialization.
Memory corruption while processing API calls to NPU with invalid input.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while maintaining memory maps of HLOS memory.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption while playing audio file having large-sized input buffer.
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.