Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory corruption while using alignments for memory allocation.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during PlayReady APP usecase while processing TA commands.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Memory corruption in HLOS while running playready use-case.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTLKGSLGPUAUXCOMMAND.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.