
CVE-2025-21424 – Use After Free in NPU
https://notcve.org/view.php?id=CVE-2025-21424
03 Mar 2025 — Memory corruption while calling the NPU driver APIs concurrently. msm_npu has a race condition between npu_host_unload_network and npu_host_exec_network_v2 that leads to memory corruption. • https://packetstorm.news/files/id/189958 • CWE-416: Use After Free •

CVE-2024-53027 – Buffer Copy Without Checking Size of Input in WLAN Host
https://notcve.org/view.php?id=CVE-2024-53027
03 Mar 2025 — Transient DOS may occur while processing the country IE. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2024-53014 – Improper Validation of Array Index in Audio
https://notcve.org/view.php?id=CVE-2024-53014
03 Mar 2025 — Memory corruption may occur while validating ports and channels in Audio driver. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-129: Improper Validation of Array Index •

CVE-2024-43057 – Use After Free in MProc
https://notcve.org/view.php?id=CVE-2024-43057
03 Mar 2025 — Memory corruption while processing command in Glink linux. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-416: Use After Free •

CVE-2024-43056 – Buffer Over-read in Hypervisor
https://notcve.org/view.php?id=CVE-2024-43056
03 Mar 2025 — Transient DOS during hypervisor virtual I/O operation in a virtual machine. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2024-43051 – Improper Authorization in SPS-HLOS
https://notcve.org/view.php?id=CVE-2024-43051
03 Mar 2025 — Information disclosure while deriving keys for a session for any Widevine use case. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-285: Improper Authorization •

CVE-2024-38426 – Improper Authentication in Modem
https://notcve.org/view.php?id=CVE-2024-38426
03 Mar 2025 — While processing the authentication message in UE, improper authentication may lead to information disclosure. • https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html • CWE-287: Improper Authentication •

CVE-2024-49839 – Buffer Over-read in WLAN Host Cmn
https://notcve.org/view.php?id=CVE-2024-49839
03 Feb 2025 — Memory corruption during management frame processing due to mismatch in T2LM info element. • https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2024-45571 – Use After Free in WLAN Host Communication
https://notcve.org/view.php?id=CVE-2024-45571
03 Feb 2025 — Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. • https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html • CWE-416: Use After Free •

CVE-2024-45569 – Improper Validation of Array Index in WLAN Host Communication
https://notcve.org/view.php?id=CVE-2024-45569
03 Feb 2025 — Memory corruption while parsing the ML IE due to invalid frame content. • https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html • CWE-129: Improper Validation of Array Index •