While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile
Memory corruption due to stack-based buffer overflow in Core
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
Memory corruption in Core due to stack-based buffer overflow.
Memory corruption in core due to stack-based buffer overflow
Information disclosure due to buffer overread in Core
Information disclosure due to buffer overread in Core
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
Memory corruption while handling payloads from remote ESL.
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
Memory corruption while handling IOCTL call from user-space to set latency level.
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while allocating memory for graphics.
Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.