Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while processing key blob passed by the user.
Memory corruption when keymaster operation imports a shared key.
Memory corruption during session sign renewal request calls in HLOS.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Memory corruption while parsing the memory map info in IOCTL calls.
Memory corruption in display driver while detaching a device.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Memory corruption during the FRS UDS generation process.
Memory corruption while reading secure file.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.