CVE-2025-47405
Published May 4, 2026Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Vendor/product archive
37 CVEs tagged to qualcomm / wsa8810 — 0 Critical, 30 High, 7 Medium, 0 Low, 0 Unrated.
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory corruption while processing a frame request from user.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU commands.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while processing user packets to generate page faults.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.