Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption while processing command in Glink linux.
Memory corruption in display driver while detaching a device.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption can occur in the camera when an invalid CID is used.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption during GNSS HAL process initialization.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Transient DOS during music playback of ALAC content.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Memory corruption when keymaster operation imports a shared key.