CVE-2025-47383
Published Mar 2, 2026Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Vendor/product archive
23 CVEs tagged to qualcomm / qcm4490 — 3 Critical, 15 High, 5 Medium, 0 Low, 0 Unrated.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while processing a config call from userspace.
Information disclosure while processing a firmware event.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
Memory corruption while processing IOCTL command to handle buffers associated with a session.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Memory corruption while processing IPA statistics, when there are no active clients registered.
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
Cryptographic issue while parsing RSA keys in COBR format.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing IE fragments from server during DTLS handshake.
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Information disclosure in Modem while processing SIB5.
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.