Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while deinitializing a HDCP session.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while handling sensor utility operations.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Cryptographic issue may occur while encrypting license data.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Transient DOS when processing target power rate tables during channel configuration.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Transient DOS may occur while parsing SSID in action frames.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Transient DOS may occur while parsing extended IE in beacon.
Information disclosure while creating MQ channels.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Memory corruption while handling file descriptor during listener registration/de-registration.
Transient DOS while parsing per STA profile in ML IE.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during the FRS UDS generation process.