Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while selecting the PLMN from SOR failed list.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Information disclosure while creating MQ channels.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS while loading the TA ELF file.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in Core while processing control functions.
Memory corruption in HLOS while running playready use-case.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Transient DOS in Modem while allocating DSM items.
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
information disclosure due to cryptographic issue in Core during RPMB read request.