CVE-2025-47403
Published May 4, 2026Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
11 CVEs tagged to qualcomm / srv1h_firmware — 0 Critical, 6 High, 5 Medium, 0 Low, 0 Unrated.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
Memory corruption while processing user packets to generate page faults.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Information disclosure while handling beacon probe frame during scan entry generation in client side.
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.