Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption in Audio during playback with speaker protection.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption while receiving a message in Bus Socket Transport Server.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during the FRS UDS generation process.
Memory corruption while reading secure file.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while retrieving the CBOR data from TA.
Memory corruption while processing video packets received from video firmware.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Transient DOS in Data Modem during DTLS handshake.
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.