CVE-2025-27030
Published Sep 24, 2025information disclosure while invoking calibration data from user space to update firmware size.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
33 CVEs tagged to qualcomm / qcs410_firmware — 1 Critical, 15 High, 17 Medium, 0 Low, 0 Unrated.
information disclosure while invoking calibration data from user space to update firmware size.
Memory corruption while processing commands from A2dp sink command queue.
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or inv…
memory corruption when an invalid firehose patch command is invoked.
Information disclosure while parsing dts header atom in Video.
Transient DOS while decoding message of size that exceeds the available system memory.
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
Memory corruption while handling payloads from remote ESL.
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, a…
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify th…
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Memory corruption in Automotive Android OS due to improper validation of array index.
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
Memory corruption in video driver due to type confusion error during video playback
Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields
Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearab…
Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO…
Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOT