Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
Memory corruption in HLOS while running playready use-case.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Memory corruption when processing cmd parameters while parsing vdev.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Information disclosure in WLAN HAL while handling command through WMI interfaces.
Information disclosure in IOE Firmware while handling WMI command.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.