Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while handling session errors from firmware.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing GPU page table switch.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Memory corruption when keymaster operation imports a shared key.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing IE fragments from server during DTLS handshake.
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Information disclosure in Modem while processing SIB5.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Transient DOS in Data Modem during DTLS handshake.