CVE-2024-53029
Published Mar 3, 2025Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Vendor/product archive
161 CVEs tagged to qualcomm / qam8255p_firmware — 4 Critical, 113 High, 44 Medium, 0 Low, 0 Unrated.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Memory corruption may occur while processing message from frontend during allocation.
Memory corruption may occur while accessing a variable during extended back to back tests.
Memory corruption may occur during communication between primary and guest VM.
Memory corruption may occur due to improper input validation in clock device.
Information disclosure while deriving keys for a session for any Widevine use case.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while reading CPU state data during guest VM suspend.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption can occur in the camera when an invalid CID is used.
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Memory corruption while configuring a Hypervisor based input virtual device.
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive…
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specif…
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
information disclosure while invoking the mailbox read API.
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer acce…
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
Memory corruption while processing IOCTL call for getting group info.
Memory corruption when user provides data for FM HCI command control operations.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.