Search Results (505 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-38293 3 Debian, Linux, Qualcomm 3 Debian Linux, Linux Kernel, Qca6698aq 2026-07-30 8.8 High
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath11k_core_halt() only reinitializes the "arvifs" list head. This will cause the list node immediately following the list head to become an invalid list node. Because the prev of that node still points to the list head "arvifs", but the next of the list head "arvifs" no longer points to that list node. When a WLAN recovery occurs during the execution of a vif removal, and it happens before the spin_lock_bh(&ar->data_lock) in ath11k_mac_op_remove_interface(), list_del() will detect the previously mentioned situation, thereby triggering a kernel panic. The fix is to remove and reinitialize all vif list nodes from the list head "arvifs" during WLAN halt. The reinitialization is to make the list nodes valid, ensuring that the list_del() in ath11k_mac_op_remove_interface() can execute normally. Call trace: __list_del_entry_valid_or_report+0xb8/0xd0 ath11k_mac_op_remove_interface+0xb0/0x27c [ath11k] drv_remove_interface+0x48/0x194 [mac80211] ieee80211_do_stop+0x6e0/0x844 [mac80211] ieee80211_stop+0x44/0x17c [mac80211] __dev_close_many+0xac/0x150 __dev_change_flags+0x194/0x234 dev_change_flags+0x24/0x6c devinet_ioctl+0x3a0/0x670 inet_ioctl+0x200/0x248 sock_do_ioctl+0x60/0x118 sock_ioctl+0x274/0x35c __arm64_sys_ioctl+0xac/0xf0 invoke_syscall+0x48/0x114 ... Tested-on: QCA6698AQ hw2.1 PCI WLAN.HSP.1.1-04591-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
CVE-2025-59610 1 Qualcomm 473 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, C-v2x 9150 and 470 more 2026-06-05 6.4 Medium
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59606 1 Qualcomm 283 Cologne, Cologne Firmware, Cq7790 and 280 more 2026-06-03 7.8 High
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59604 1 Qualcomm 531 Ar8035, Ar8035 Firmware, Cologne and 528 more 2026-06-02 7.8 High
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-59605 1 Qualcomm 281 Ar8035, Ar8035 Firmware, Csra6620 and 278 more 2026-06-02 7.8 High
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59609 1 Qualcomm 375 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Ar8035 and 372 more 2026-06-02 5.5 Medium
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2026-24085 1 Qualcomm 547 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Apq8098 and 544 more 2026-06-02 7.2 High
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2026-24087 1 Qualcomm 431 Ar8031, Ar8031 Firmware, Ar8035 and 428 more 2026-06-02 7.2 High
Memory corruption while processing fastboot OEM commands.
CVE-2026-24088 1 Qualcomm 493 Ar9380, Ar9380 Firmware, Csr8811 and 490 more 2026-06-02 8.2 High
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24089 1 Qualcomm 439 Ar8031, Ar8031 Firmware, Ar8035 and 436 more 2026-06-02 7.2 High
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24090 1 Qualcomm 435 Ar8031, Ar8031 Firmware, Ar8035 and 432 more 2026-06-02 7.1 High
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24091 1 Qualcomm 547 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Apq8098 and 544 more 2026-06-02 7.2 High
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24092 1 Qualcomm 437 Ar8031, Ar8031 Firmware, Ar8035 and 434 more 2026-06-02 7.2 High
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24082 1 Qualcomm 353 Ar8031, Ar8031 Firmware, Ar8035 and 350 more 2026-05-12 7.8 High
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
CVE-2025-47401 1 Qualcomm 491 Ar8035, Ar8035 Firmware, Cologne and 488 more 2026-05-06 6.5 Medium
Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-47403 1 Qualcomm 515 Ar8035, Ar8035 Firmware, Cologne and 512 more 2026-05-06 6.5 Medium
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47404 1 Qualcomm 377 215 Mobile, 215 Mobile Firmware, 5g Fixed Wireless Access and 374 more 2026-05-06 6.5 Medium
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2026-21385 1 Qualcomm 475 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Apq8098 and 472 more 2026-04-18 7.8 High
Memory corruption while using alignments for memory allocation.
CVE-2025-47389 1 Qualcomm 363 Ar8035, Ar8035 Firmware, Cologne and 360 more 2026-04-09 7.8 High
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2025-47391 1 Qualcomm 203 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 200 more 2026-04-09 7.8 High
Memory corruption while processing a frame request from user.