Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory Corruption in Audio while invoking callback function in driver from ADSP.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Transient DOS in WLAN Firmware while parsing a NAN management frame.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Transient DOS in WLAN Firmware while parsing rsn ies.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Memory corruption while invoking callback function of AFE from ADSP.
Memory corruption while parsing the ADSP response command.
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Memory corruption due to improper validation of array index in WLAN HAL when received lmitemNum is out of range.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
Memory corruption in Graphics while importing a file.
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.