Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
The camgetdevicepriv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.