Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing GPU page table switch.
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
Transient DOS in Data Modem during DTLS handshake.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption in Audio during playback with speaker protection.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS while processing TID-to-link mapping IE elements.
Memory corruption when keymaster operation imports a shared key.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.