CVE-2025-47383
Published Mar 2, 2026Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Vendor/product archive
76 CVEs tagged to qualcomm / qca8337 — 9 Critical, 53 High, 14 Medium, 0 Low, 0 Unrated.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while selecting the PLMN from SOR failed list.
Information disclosure while opening a fastrpc session when domain is not sanitized.
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
Memory corruption while decoding of OTA messages from T3448 IE.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Information disclosure while processing IO control commands.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or inv…
Memory corruption while processing concurrent IOCTL calls.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing IE fragments from server during DTLS handshake.
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Information disclosure in Modem while processing SIB5.
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.