Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while deinitializing a HDCP session.
Memory corruption while processing a config call from userspace.
Memory corruption while handling sensor utility operations.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while processing a frame request from user.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Information disclosure while creating MQ channels.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while allocating buffers in DSP service.
Memory corruption while processing a malformed license file during reboot.