« Back to list

Qualcomm

Qualcomm Msm8996au Firmware: vulnerabilities and CVEs

Qualcomm Msm8996au Firmware has 707 published vulnerabilities, 4 of them in the last 12 months. 192 are rated critical and 4 are listed by CISA as actively exploited.

CVEs707
Last 12 months4
Critical192
Actively exploited4

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33107High (7.8)0.74%⚠ Active exploitationDec 5, 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
CVE-2020-11261High (7.8)1.6%⚠ Active exploitationJun 9, 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1906Medium (5.5)0.52%⚠ Active exploitationMay 7, 2021
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1905High (7.8)1.5%⚠ Active exploitationMay 7, 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-47320High (7.8)0.08%—Dec 18, 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47362Medium (6.1)0.08%—Nov 4, 2025
Information disclosure while processing message from client with invalid payload.
CVE-2025-27074High (7.8)0.08%—Nov 4, 2025
Memory corruption while processing a GP command response.
CVE-2025-27053High (7.8)0.09%—Oct 9, 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-47318High (7.5)0.21%—Sep 24, 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-21483Critical (9.8)0.40%—Sep 24, 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21488High (8.2)0.27%—Sep 24, 2025
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-21487High (8.2)0.26%—Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484High (8.2)0.26%—Sep 24, 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482High (7.1)0.08%—Sep 24, 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27062High (7.8)0.08%—Aug 6, 2025
Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2025-21427High (8.2)0.22%—Jul 8, 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2024-53026High (8.2)0.30%—Jun 3, 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53020High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53013Medium (6.6)0.09%—Jun 3, 2025
Memory corruption may occur while processing voice call registration with user.
CVE-2024-45562High (7.8)0.11%—May 6, 2025
Memory corruption during concurrent access to server info object due to unprotected critical field.
CVE-2025-21430High (7.5)0.26%—Apr 7, 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2025-21429High (7.5)0.26%—Apr 7, 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428High (7.5)0.25%—Apr 7, 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-45552High (8.2)0.26%—Apr 7, 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-45543Medium (6.6)0.11%—Apr 7, 2025
Memory corruption while accessing MSM channel map and mixer functions.
CVE-2024-53030High (7.8)0.12%—Mar 3, 2025
Memory corruption while processing input message passed from FE driver.
CVE-2024-53027High (7.5)0.30%—Mar 3, 2025
Transient DOS may occur while processing the country IE.
CVE-2024-38426Medium (5.3)0.27%—Mar 3, 2025
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-38416Medium (5.5)0.10%—Feb 3, 2025
Information disclosure during audio playback.
CVE-2024-45555High (7.8)0.14%—Jan 6, 2025
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a…
CVE-2024-33067Medium (5.5)0.10%—Jan 6, 2025
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
CVE-2017-11076Critical (9.8)0.35%—Nov 26, 2024
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
CVE-2024-38423High (7.8)0.10%—Nov 4, 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422High (7.8)0.10%—Nov 4, 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation14
  2. T1190 Exploit Public-Facing Application14
  3. T1059 Command and Scripting Interpreter12
  4. T1005 Data from Local System8
  5. T1499.004 Application or System Exploitation5
  6. T1499 Endpoint Denial of Service1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm