Memory corruption while processing MBSSID beacon containing several subelement IE.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption in Audio during playback with speaker protection.
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while handling user packets during VBO bind operation.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption while allocating memory in HGSL driver.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Memory corruption in Graphics while importing a file.
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption when keymaster operation imports a shared key.
Memory corruption while handling session errors from firmware.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.