Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
Memory corruption while selecting the PLMN from SOR failed list.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Core while processing control functions.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption due to double free in core while initializing the encryption key.
Information disclosure in Modem while processing SIB5.
Information Disclosure while parsing beacon frame in STA.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while decoding of OTA messages from T3448 IE.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption in Kernel while handling GPU operations.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption while allocating memory in HGSL driver.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.