CVE-2026-25260
Published Jun 1, 2026Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
21 CVEs tagged to qualcomm / sd865_5g — 1 Critical, 15 High, 5 Medium, 0 Low, 0 Unrated.
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
Memory corruption while processing multiple IOCTL command for escape operations.
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory corruption while processing specific files in Powerline Communication Firmware.
Memory corruption while submitting blob data to kernel space though IOCTL.
Memory corruption while processing manipulated payload in video firmware.
Memory corruption while processing I2C settings in Camera driver.
Memory corruption while reading the FW response from the shared queue.
Memory corruption during concurrent buffer access due to modification of the reference count.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer acce…
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, a…
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify th…
Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
Memory corruption in audio due to use after free while managing buffers from internal cache in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile