CVE-2025-47375
Published Mar 2, 2026Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Vendor/product archive
26 CVEs tagged to qualcomm / sa8195p — 0 Critical, 13 High, 13 Medium, 0 Low, 0 Unrated.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while handling sensor utility operations.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Memory corruption may occur while processing voice call registration with user.
Memory corruption while reading the FW response from the shared queue.
Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption while reading secure file.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption during the network scan request.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Memory corruption while releasing shared resources in MinkSocket listener thread.
Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).
Memory corruption in Audio while validating and mapping metadata.
An app with non-privileged access can change global system brightness and cause undesired system behavior.
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Memory corruption in Audio due to incorrect type cast during audio use-cases.
Memory corruption in HAB Memory management due to broad system privileges via physical address.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.
Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.
Memory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables
Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto