Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
There may be information disclosure during memory re-allocation in TZ Secure OS.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS in Modem while allocating DSM items.
Transient DOS in WLAN Firmware while parsing rsn ies.
Improper Access to the VM resource manager can lead to Memory Corruption.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption in Core while processing control functions.
Transient DOS while parse fils IE with length equal to 1.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Information disclosure in WLAN HAL while handling command through WMI interfaces.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Memory corruption in HLOS while running playready use-case.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption in Audio during playback with speaker protection.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.