CVE-2026-24077
Published Aug 4, 2026Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
36 CVEs tagged to qualcomm / wcn3980_firmware — 1 Critical, 22 High, 13 Medium, 0 Low, 0 Unrated.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption during the network scan request.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Transient DOS during music playback of ALAC content.