Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory corruption while processing video packets received from video firmware.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption in Audio during playback with speaker protection.
The camgetdevicepriv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption in modem due to buffer overflow while processing a PPP packet
Information Disclosure in Graphics during GPU context switch.
Memory corruption due to use after free in trusted application environment.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.