Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Transient DOS while processing an ANQP message.
Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Transient DOS may occur while parsing SSID in action frames.
Memory corruption while deinitializing a HDCP session.
Transient DOS in WLAN Firmware while parsing a NAN management frame.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Transient DOS in WLAN Firmware while parsing rsn ies.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS in WLAN Firmware while parsing a BTM request.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Memory corruption in Core Services while executing the command for removing a single event listener.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Information disclosure in WLAN HAL while handling command through WMI interfaces.
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Information disclosure in IOE Firmware while handling WMI command.
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
Memory corruption when processing cmd parameters while parsing vdev.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
Information exposure in DSP services due to improper handling of freeing memory
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
Memory corruption due to buffer copy without checking size of input in modem while receiving WMIREQUESTSTATSCMDID command.
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.