An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4nat'
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
Possible out of bound access in audio module due to lack of validation of user provided input.
Certain unprivileged processes are able to perform IOCTL calls.
The camgetdevicepriv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption in modem due to buffer overflow while processing a PPP packet
Information Disclosure in Graphics during GPU context switch.
Memory corruption due to use after free in trusted application environment.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
Memory corruption due to improper access control in Qualcomm IPC.
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
Information exposure in DSP services due to improper handling of freeing memory
Memory corruption in video driver due to type confusion error during video playback
Memory corruption in display due to double free while allocating frame buffer memory
Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields
Denial of service while processing fastboot flash command on mmc due to buffer over read
Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device.
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.
Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables