Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Audio during playback with speaker protection.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption while using alignments for memory allocation.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.