Memory corruption due to double free in Core while mapping HLOS address to the list.
Assertion occurs while processing Reconfiguration message due to improper validation
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Information disclosure in Kernel due to indirect branch misprediction.
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
Transient DOS due to improper authorization in Modem
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
Memoru corruption in Audio when ADSP sends input during record use case.
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
Memory corruption in Graphics while importing a file.
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external components in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile