Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while deinitializing a HDCP session.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Memory corruption while processing a config call from userspace.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Cryptographic issue may occur while encrypting license data.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while processing a frame request from user.
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Transient DOS when processing target power rate tables during channel configuration.
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
Memory corruption while allocating buffers in DSP service.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.