Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption while processing command in Glink linux.
Memory corruption in display driver while detaching a device.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption can occur in the camera when an invalid CID is used.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
Memory corruption while validating number of devices in Camera kernel .
Memory corruption while configuring a Hypervisor based input virtual device.
Information disclosure while processing IO control commands.
Information disclosure while processing information on firmware image during core initialization.
Memory corruption while parsing the memory map info in IOCTL calls.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption during GNSS HAL process initialization.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.