Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while decoding of OTA messages from T3448 IE.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption while processing user packets to generate page faults.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
Cryptographic issue may occur while encrypting license data.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Information disclosure while parsing the OCI IE with invalid length.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.