Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
Memory corruption while using alignments for memory allocation.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during video playback when video session open fails with time out error.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Transient DOS while processing an ANQP message.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Memory corruption while handling file descriptor during listener registration/de-registration.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.