Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption in display driver while detaching a device.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption can occur in the camera when an invalid CID is used.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Memory corruption while validating number of devices in Camera kernel .
Memory corruption while processing frame command IOCTL calls.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while processing IOCTL calls to unmap the buffers.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Memory corruption while handling session errors from firmware.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Transient DOS while processing the CU information from RNR IE.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption during GNSS HAL process initialization.
Information disclosure while sending implicit broadcast containing APP launch information.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption while allocating memory in HGSL driver.
Memory corruption while processing IOCTL call to set metainfo.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.