CVE-2026-25268
Published Jul 6, 2026Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
79 CVEs tagged to qualcomm / wsa8835 — 0 Critical, 51 High, 28 Medium, 0 Low, 0 Unrated.
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.
Memory corruption while performing sensor register read operations.
Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.
Memory corruption while processing an IOCTL command with an arbitrary address.
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
Information disclosure while capturing logs as eSE debug messages are logged.
Memory corruption while processing camera TPG write request.
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
Memory corruption while processing IOCTL calls.
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU commands.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.