PatchSiren

Qualcomm, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-25292

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:25.183Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-25292, involves memory corruption in the fastboot command handler for audio framework configuration, affecting Qualcomm products. The vulnerability could lead to denial of service [truncated]

CRITICAL Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-25289

The CVE-2026-25289 record describes a critical memory corruption vulnerability in device capability extended attributes processing. This vulnerability, with a CVSS score of 9.6, could potentially allow for remote code execution. Affected products likely include devices with Qualcomm chipsets, particularly those in critical infrastructure or high-risk exposure. The CVE record was published on 2026-08-04T16 [truncated]

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-25288

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:24.693Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects multiple Qualcomm devices and is caused by improper handling of short target wake time channel usage response frames with insufficient packet sizes, potentially leading to transient [truncated]

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-24083

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:24.123Z and has not been modified since then. CVE-2026-24083 is a high-severity memory corruption vulnerability in an IOCTL device driver. The vulnerability occurs when processing device driver requests with invalid arguments. According to the NVD, the vulnerability has a CVSS score of 7.8 [truncated]

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-24080

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:23.770Z and has not been modified since then. This memory corruption vulnerability exists in the fingerprint TA of Qualcomm products when handling malformed request parameters. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Affected operators, platforms, vulne [truncated]

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-24079

CVE-2026-24079 is a high-severity cryptographic issue affecting Qualcomm products, occurring when processing registration requests with malformed or missing authentication parameters. Organizations utilizing Qualcomm products should be aware of this vulnerability and verify their exposure. The CVE record was published on 2026-08-04T16:16:23.453Z and has not been modified since then. Qualcomm has provided [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-24077

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:23.050Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-24077, involves Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. Affected products include various Qualc [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-24076

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:22.920Z and has not been modified since then. This memory corruption vulnerability, caused by processing registry values with incorrect types using a direct query method, affects organizations using systems potentially impacted. Operators managing affected products, platform administrators, [truncated]

HIGH Qualcomm, Inc. CVE published 2026-08-04

CVE-2026-21366

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T16:16:22.780Z and has not been modified since then. This memory corruption vulnerability exists while processing a packet with a size close to the maximum allowed value, classified as HIGH severity with a CVSS score of 7.8. Organizations using products from Qualcomm or other vendors that may be a [truncated]

HIGH Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-25271

A high-severity memory corruption vulnerability, CVE-2026-25271, was made public on 2026-07-06T21:16:54.903Z. The vulnerability is caused by improper handling of modified values between check and use when processing asynchronous input parameters. This issue affects Qualcomm products and could lead to memory corruption. Users should review the vendor's security bulletin for potential impacts and apply miti [truncated]

HIGH Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-25268

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-06T21:16:54.730Z and has not been modified since then. This HIGH severity vulnerability affects products from Qualcomm, potentially leading to Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. Organizations using Qualcomm products should revi [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21384

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-06T21:16:54.097Z and has not been modified since then. This memory corruption vulnerability occurs when updating prepared commands with invalid port indices based on user space input that exceeds supported read client limits. Defenders should focus on Qualcomm products and review the July 2026 secur [truncated]

HIGH Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21383

A cryptographic issue was found in various Qualcomm products, related to the use of a static initialization vector for AES-GCM key wrapping. This could potentially compromise the security of encrypted data, as AES-GCM requires a unique initialization vector for each encryption operation to ensure security. The affected products include multiple Qualcomm chipsets and firmware versions. Users of these produ [truncated]

HIGH Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21379

CVE-2026-21379 is a high-severity memory corruption vulnerability with a CVSS score of 7.8. The vulnerability occurs when allocating memory with sizes that exceed the maximum allowed value. This CVE record was published on 2026-07-06T21:16:53.850Z and has not been modified since then. Security teams and administrators responsible for systems using Qualcomm products should assess and prioritize patching fo [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21370

CVE-2026-21370 is a memory corruption vulnerability that occurs when validating input batch size and buffer plane count exceeds maximum allowed values. The CVSS score is 5.3, indicating a medium severity vulnerability. This vulnerability affects Qualcomm products, and organizations using these products should review the vendor bulletin for patching guidance. The CVE record was published on 2026-07-06T21:1 [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21369

CVE-2026-21369 is a memory corruption vulnerability that occurs when handling flash commands due to outdated LED count values being used after userspace modification. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The CVE record was published on 2026-07-06T21:16:53.553Z and has n [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2026-21368

A memory corruption vulnerability was discovered when parsing JPEG commands due to unaccounted extra writes to the buffer during validation checks. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability affects Qualcomm products and could allow an attacker to execute arbitrary code. Security teams and administrators should be aware of this vulnerability and take necessa [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2025-59617

A memory corruption vulnerability was reported when processing multiple IOCTL calls with the same buffer file descriptor input. This vulnerability has been assigned a CVSS score of 6.6 and MEDIUM severity. The CVE record was published on 2026-07-06T21:16:52.653Z and has not been modified since then. The NVD entry is currently marked as Received. Security teams and administrators responsible for systems us [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2025-59616

A memory corruption vulnerability exists in an unspecified product due to improper handling of multiple IOCTL calls with the same buffer file descriptor input. This issue arises from accessing memory that has already been freed, potentially leading to system instability or code execution. The vulnerability is caused by a memory corruption issue when processing multiple IOCTL calls with the same buffer fil [truncated]

MEDIUM Qualcomm, Inc. CVE published 2026-07-06

CVE-2025-59615

A memory corruption vulnerability exists due to improper synchronization when invoking device input/output control operations for mapping and unmapping persistent memory buffers. This CVE record was published on 2026-07-06T21:16:52.077Z and has not been modified since then. The vulnerability affects devices with Qualcomm processors. Users should review the vendor's security bulletin for patches and apply [truncated]

HIGH Qualcomm, Inc. CVE published 2026-05-04

CVE-2026-24082

CVE-2026-24082 is a high-severity memory corruption vulnerability in Qualcomm products. The vulnerability occurs when copying data from a freed source while executing a performance counter deselect operation. This vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. Qualcomm has released a patch for this vulnerability, which is available in the May 2026 security bulletin.

HIGH Qualcomm, Inc. CVE published 2025-02-11

CVE-2023-43522

CVE-2023-43522 affects multiple Siemens SCALANCE W700 wireless devices and can cause a transient denial of service during key unwrapping when the encrypted key is empty or NULL. The advisory rates the issue HIGH with CVSS 3.1 base score 7.5 because it is network-reachable, requires no privileges or user interaction, and impacts availability. Siemens lists update to V3.0.0 or later as the fix for the affec [truncated]