Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure during audio playback.
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesnt validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Memory corruption while handling session errors from firmware.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing GPU page table switch.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Transient DOS during music playback of ALAC content.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Transient DOS in Data Modem during DTLS handshake.
Memory corruption while receiving a message in Bus Socket Transport Server.