Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
Memory corruption while selecting the PLMN from SOR failed list.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Core while processing control functions.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Information disclosure in Modem while processing SIB5.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Memory corruption in core services when Diag handler receives a command to configure event listeners.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption in Audio during playback with speaker protection.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption while receiving a message in Bus Socket Transport Server.
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Memory corruption while processing key blob passed by the user.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.