Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory corruption while using alignments for memory allocation.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTLKGSLGPUAUXCOMMAND.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Transient DOS when MAC configures config id greater than supported maximum value.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in Core while processing control functions.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.