Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Memory corruption when keymaster operation imports a shared key.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in Core while processing control functions.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption in HLOS while running playready use-case.
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTLKGSLGPUAUXCOMMAND.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
Memory corruption when processing cmd parameters while parsing vdev.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Information disclosure in WLAN HAL while handling command through WMI interfaces.
Information disclosure in IOE Firmware while handling WMI command.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.