Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while selecting the PLMN from SOR failed list.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Information disclosure while creating MQ channels.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Transient DOS while loading the TA ELF file.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in Core while processing control functions.
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Information disclosure in Modem while processing SIB5.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Transient DOS in Data Modem during DTLS handshake.
Memory corruption while receiving a message in Bus Socket Transport Server.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.