Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption while sending SMS from AP firmware.
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Memory Corruption in Audio while invoking callback function in driver from ADSP.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Transient DOS in WLAN Firmware while parsing a NAN management frame.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Transient DOS in WLAN Firmware while parsing rsn ies.
Memory corruption due to improper validation of array index in WLAN HAL when received lmitemNum is out of range.
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
Memory corruption in Linux while sending DRM request.
Memory corruption in Linux android due to double free while calling unregister provider after register call.
information disclosure due to cryptographic issue in Core during RPMB read request.
Assertion occurs while processing Reconfiguration message due to improper validation