Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while retrieving the CBOR data from TA.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption during concurrent buffer access due to modification of the reference count.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during the FRS UDS generation process.
Memory corruption while reading secure file.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure during audio playback.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesnt validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.