Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesnt validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing GPU page table switch.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Transient DOS during music playback of ALAC content.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS while processing TID-to-link mapping IE elements.
Memory corruption when keymaster operation imports a shared key.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Transient DOS in Data Modem during DTLS handshake.
Memory corruption while receiving a message in Bus Socket Transport Server.