Memory corruption while decoding of OTA messages from T3448 IE.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while processing the update SIM PB records request.
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Transient DOS while processing the CU information from RNR IE.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption during GNSS HAL process initialization.
Memory corruption while allocating memory in HGSL driver.
Memory corruption while processing IOCTL call to set metainfo.
Transient DOS during music playback of ALAC content.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS while processing TID-to-link mapping IE elements.
Memory corruption when keymaster operation imports a shared key.
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
Memory corruption during session sign renewal request calls in HLOS.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Information Disclosure while parsing beacon frame in STA.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.