CVE-2025-47383
Published Mar 2, 2026Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
92 CVEs tagged to qualcomm / qca8337_firmware — 11 Critical, 63 High, 18 Medium, 0 Low, 0 Unrated.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS while parsing video packets received from the video firmware.
Transient DOS while processing video packets received from video firmware.
Memory corruption while selecting the PLMN from SOR failed list.
Information disclosure while opening a fastrpc session when domain is not sanitized.
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
Memory corruption while decoding of OTA messages from T3448 IE.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Information disclosure while processing IO control commands.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or inv…
Memory corruption while processing the update SIM PB records request.
Memory corruption while processing concurrent IOCTL calls.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Memory corruption in Hypervisor when platform information mentioned is not aligned.
Memory corruption when more scan frequency list or channels are sent from the user space.
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing IE fragments from server during DTLS handshake.