Transient DOS while loading the TA ELF file.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Transient DOS in WLAN Firmware while parsing a NAN management frame.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory Corruption in HLOS while registering for key provisioning notify.
Transient DOS in WLAN Firmware while parsing rsn ies.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Memory corruption in WLAN HAL while handling command through WMI interfaces.
Memory corruption due to improper validation of array index in WLAN HAL when received lmitemNum is out of range.
Memory corruption in WLAN HAL while parsing WMI command parameters.
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
information disclosure due to cryptographic issue in Core during RPMB read request.
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Information disclosure in Kernel due to indirect branch misprediction.
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
Transient DOS in WLAN Firmware while processing frames with missing header fields.
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity