CVE-2026-24077
Published Aug 4, 2026Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
33 CVEs tagged to qualcomm / wcn3950_firmware — 1 Critical, 27 High, 5 Medium, 0 Low, 0 Unrated.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
Cryptographic issue may occur while encrypting license data.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption during the FRS UDS generation process.
Memory corruption while processing IPA statistics, when there are no active clients registered.
Memory corruption while processing GPU page table switch.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while processing user packets to generate page faults.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Memory corruption when keymaster operation imports a shared key.