Memory corruption in Core while processing control functions.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption in core services when Diag handler receives a command to configure event listeners.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while loading an ELF segment in TEE Kernel.
Improper Access to the VM resource manager can lead to Memory Corruption.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption while allocating memory in HGSL driver.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
Memory Corruption in HLOS while registering for key provisioning notify.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption when keymaster operation imports a shared key.
Memory corruption during session sign renewal request calls in HLOS.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Memory corruption may occur while accessing a variable during extended back to back tests.