CVE-2025-21452
Published Aug 6, 2025Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
57 CVEs tagged to qualcomm / qca6431_firmware — 4 Critical, 44 High, 9 Medium, 0 Low, 0 Unrated.
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
Transient DOS in Modem while triggering a camping on an 5G cell.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
Memory corruption due to improper validation of array index in Multi-mode call processor.
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
Denial of service in MODEM due to improper pointer handling
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caches in Snapdragon Auto, Snapdragon Com…