CVE-2026-24077
Published Aug 4, 2026Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
37 CVEs tagged to qualcomm / wcn3988_firmware — 1 Critical, 26 High, 10 Medium, 0 Low, 0 Unrated.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
Memory corruption while processing a frame request from user.
Cryptographic issue may occur while encrypting license data.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption during the FRS UDS generation process.
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption during the network scan request.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.