Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while processing TPC target power table in FTM TPC.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Information disclosure while parsing the OCI IE with invalid length.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption when the channel ID passed by user is not validated and further used.
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
Memory corruption while maintaining memory maps of HLOS memory.
Memory corruption while parsing the memory map info in IOCTL calls.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during the FRS UDS generation process.
Memory corruption while reading secure file.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Memory corruption during concurrent buffer access due to modification of the reference count.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while retrieving the CBOR data from TA.
Memory corruption while processing video packets received from video firmware.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
Transient DOS while processing received beacon frame.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.