Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Transient DOS when MAC configures config id greater than supported maximum value.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while selecting the PLMN from SOR failed list.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Transient DOS while loading the TA ELF file.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in Core while processing control functions.