Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while reading ACPI config through the user mode app.
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
Memory corruption while station LL statistic handling.
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.