Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Core while processing control functions.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Memory corruption while loading an ELF segment in TEE Kernel.
Improper Access to the VM resource manager can lead to Memory Corruption.
Memory corruption in Automotive Multimedia due to improper access control in HAB.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.