Memory corruption while processing a GP command response.
Memory corruption during PlayReady APP usecase while processing TA commands.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4nat'
Information disclosure possible while audio playback.
Information disclosure due to uninitialized variable.
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
Certain unprivileged processes are able to perform IOCTL calls.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Memory corruption in HLOS while running playready use-case.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Information disclosure in IOE Firmware while handling WMI command.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
information disclosure due to cryptographic issue in Core during RPMB read request.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.