CVE-2025-21488
Published Sep 24, 2025Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
31 CVEs tagged to qualcomm / qca6564a — 2 Critical, 20 High, 9 Medium, 0 Low, 0 Unrated.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Memory corruption while sound model registration for voice activation with audio kernel driver.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while processing input message passed from FE driver.
Information disclosure during audio playback.
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive…
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
Weak configuration in Automotive while VM is processing a listener request from TEE.
Transient DOS in Audio while remapping channel buffer in media codec decoding.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in Automotive GPU while querying a gsl memory node.
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.
Memory corruption due to use after free in trusted application environment.
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.
Memory corruption in Automotive due to improper input validation.
Memory corruption in display due to double free while allocating frame buffer memory
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto
Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto
Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto
Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile
Possible out of bound memory access due to improper boundary check while creating HSYNC fence in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indu…