Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in HLOS while running playready use-case.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.