Filtered by vendor Qualcomm
Subscriptions
Total
2522 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-24077 | 1 Qualcomm | 289 Aqt1000, Aqt1000 Firmware, Ar8035 and 286 more | 2026-08-09 | 6.5 Medium |
| Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | ||||
| CVE-2026-24079 | 1 Qualcomm | 287 Ar8035, Ar8035 Firmware, Csra6620 and 284 more | 2026-08-07 | 8.1 High |
| Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | ||||
| CVE-2026-24076 | 1 Qualcomm | 105 Aqt1000, Aqt1000 Firmware, Cologne and 102 more | 2026-08-06 | 6.7 Medium |
| Memory Corruption when processing registry values with incorrect types using a direct query method. | ||||
| CVE-2026-25292 | 1 Qualcomm | 423 Ar8031, Ar8031 Firmware, Ar8035 and 420 more | 2026-08-05 | 7.6 High |
| Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | ||||
| CVE-2026-24080 | 1 Qualcomm | 73 Cologne, Cologne Firmware, Fastconnect 6700 and 70 more | 2026-08-05 | 7.8 High |
| Memory Corruption when handling malformed request parameters in the fingerprint TA. | ||||
| CVE-2026-25288 | 1 Qualcomm | 109 Cologne, Cologne Firmware, Cq7790 and 106 more | 2026-08-05 | 7.4 High |
| Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||||
| CVE-2026-25289 | 1 Qualcomm | 403 Ar8035, Ar8035 Firmware, Cologne and 400 more | 2026-08-05 | 9.6 Critical |
| Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | ||||
| CVE-2026-24078 | 1 Qualcomm | 295 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Ar8035 and 292 more | 2026-08-04 | 6.5 Medium |
| Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||||
| CVE-2026-24083 | 1 Qualcomm | 7 Qam8295p, Qam8295p Firmware, Qca6696 and 4 more | 2026-08-04 | 7.8 High |
| Memory Corruption while processing IOCTL device driver requests with invalid arguments. | ||||
| CVE-2026-24084 | 1 Qualcomm | 257 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Aqt1000 and 254 more | 2026-08-04 | 7.5 High |
| Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | ||||
| CVE-2026-21366 | 1 Qualcomm | 67 Lemans Au Lgit, Lemans Au Lgit Firmware, Lemansau and 64 more | 2026-08-04 | 7.8 High |
| Memory corruption while processing a packet with a size close to the maximum allowed value. | ||||
| CVE-2025-38293 | 3 Debian, Linux, Qualcomm | 3 Debian Linux, Linux Kernel, Qca6698aq | 2026-07-30 | 8.8 High |
| In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath11k_core_halt() only reinitializes the "arvifs" list head. This will cause the list node immediately following the list head to become an invalid list node. Because the prev of that node still points to the list head "arvifs", but the next of the list head "arvifs" no longer points to that list node. When a WLAN recovery occurs during the execution of a vif removal, and it happens before the spin_lock_bh(&ar->data_lock) in ath11k_mac_op_remove_interface(), list_del() will detect the previously mentioned situation, thereby triggering a kernel panic. The fix is to remove and reinitialize all vif list nodes from the list head "arvifs" during WLAN halt. The reinitialization is to make the list nodes valid, ensuring that the list_del() in ath11k_mac_op_remove_interface() can execute normally. Call trace: __list_del_entry_valid_or_report+0xb8/0xd0 ath11k_mac_op_remove_interface+0xb0/0x27c [ath11k] drv_remove_interface+0x48/0x194 [mac80211] ieee80211_do_stop+0x6e0/0x844 [mac80211] ieee80211_stop+0x44/0x17c [mac80211] __dev_close_many+0xac/0x150 __dev_change_flags+0x194/0x234 dev_change_flags+0x24/0x6c devinet_ioctl+0x3a0/0x670 inet_ioctl+0x200/0x248 sock_do_ioctl+0x60/0x118 sock_ioctl+0x274/0x35c __arm64_sys_ioctl+0xac/0xf0 invoke_syscall+0x48/0x114 ... Tested-on: QCA6698AQ hw2.1 PCI WLAN.HSP.1.1-04591-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 | ||||
| CVE-2026-21369 | 1 Qualcomm | 219 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 216 more | 2026-07-09 | 5.3 Medium |
| Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | ||||
| CVE-2026-21384 | 1 Qualcomm | 159 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 156 more | 2026-07-08 | 5.3 Medium |
| Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | ||||
| CVE-2025-59615 | 1 Qualcomm | 121 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 118 more | 2026-07-08 | 6.6 Medium |
| Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. | ||||
| CVE-2025-59616 | 1 Qualcomm | 97 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 94 more | 2026-07-08 | 6.6 Medium |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. | ||||
| CVE-2025-59617 | 1 Qualcomm | 97 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 94 more | 2026-07-07 | 6.6 Medium |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. | ||||
| CVE-2026-21368 | 1 Qualcomm | 183 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 180 more | 2026-07-07 | 5.3 Medium |
| Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. | ||||
| CVE-2026-21370 | 1 Qualcomm | 183 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 180 more | 2026-07-07 | 5.3 Medium |
| Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | ||||
| CVE-2026-25271 | 1 Qualcomm | 43 Cologne, Cologne Firmware, Fastconnect 6900 and 40 more | 2026-07-07 | 7.8 High |
| Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. | ||||