Where
-Infinity
0
Severity
9.8
Out-of-bounds Read
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while selecting the PLMN from SOR failed list.

First published (updated )
Severity
9.8
Buffer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Cryptographic issue occurs due to use of insecure connection method while downloading.

First published (updated )
Severity
8.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

1 / 2
Source: MITRE
First published (updated )
Severity
8.6
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

1 / 2
Source: MITRE
First published (updated )
Severity
8.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Cryptographic issue may occur while encrypting license data.

First published (updated )
Severity
8.2
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure while parsing the OCI IE with invalid length.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing voice packet with arbitrary data received from ADSP.

First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption during GNSS HAL process initialization.

First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing GPU commands.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption when invalid input is passed to invoke GPU Headroom API call.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.

First published (updated )
Severity
7.8
EPSS
0.02%
Out-of-bounds Read
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.

First published (updated )
Severity
7.8
EPSS
0.02%
Out-of-bounds Read
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while power-up or power-down sequence of the camera sensor.

First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.

First published (updated )
Severity
7.8
Null Pointer Dereference
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in display driver while detaching a device.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while calling the NPU driver APIs concurrently.

First published (updated )
Severity
7.8
Out-of-bounds Read
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption may occur while validating ports and channels in Audio driver.

First published (updated )
Severity
7.8
Input Validation
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption during the FRS UDS generation process.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while reading secure file.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.

First published (updated )
Severity
7.8
Double Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while retrieving the CBOR data from TA.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing data packets in diag received from Unix clients.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing video packets received from video firmware.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203