CVE-2025-47405High· 7.8▾ TwilightMemory corruption when processing camera sensor input/output control codes with invalid output buffers.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.07%
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
fastconnect_6900_firmwarefastconnect_7800_firmwareiqx5121_firmwareiqx7181_firmwareqca0000_firmwaresc8380xp_firmwaresd865_5g_firmwaresnapdragon_xr2_5g_firmwaresnapdragon_xr2+_gen_1_firmwarewcd9380_firmwarewcd9385_firmwarewsa8810_firmwarewsa8815_firmwarewsa8840_firmwarewsa8845_firmwarewsa8845h_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-47408High· 7.8Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-47407High· 7.8Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47406Medium· 6.1Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47404Medium· 6.5Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47403Medium· 6.5Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47401Medium· 6.5Transient DOS when processing target power rate tables during channel configuration.