Where
-Infinity
0
Severity
9.8
Out-of-bounds Read
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while selecting the PLMN from SOR failed list.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Modem while processing security related configuration before AS Security Exchange.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory Corruption in Multi-mode Call Processor while processing bit mask API.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN Host while processing RRM beacon on the AP.

First published (updated )
Severity
9.6
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

First published (updated )
Severity
9.3
AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Memory corruption in Core while processing control functions.

First published (updated )
Severity
9.3
Input Validation
AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Memory corruption in Core Services while executing the command for removing a single event listener.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure in Modem while processing SIB5.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Information Disclosure while parsing beacon frame in STA.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

First published (updated )
Severity
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Memory corruption while decoding of OTA messages from T3448 IE.

First published (updated )
Severity
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

First published (updated )
Severity
9
Input Validation
AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Memory corruption in core services when Diag handler receives a command to configure event listeners.

First published (updated )
Severity
8.8
Integer Overflow
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

First published (updated )
Severity
8.8
Buffer Overflow
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Memory corruption while loading an ELF segment in TEE Kernel.

First published (updated )
Severity
8.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Improper Access to the VM resource manager can lead to Memory Corruption.

First published (updated )
Severity
8.4
Double Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing IOCTL call to set metainfo.

First published (updated )
Severity
8.4
Integer Overflow
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while allocating memory in HGSL driver.

First published (updated )
Severity
8.4
Use After Free
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

First published (updated )
Severity
8.4
Out-of-bounds Read
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Cryptographic issue may occur while encrypting license data.

First published (updated )
Severity
8.4
Input Validation
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory Corruption in HLOS while registering for key provisioning notify.

First published (updated )
Severity
8.4
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in DSP Service during a remote call from HLOS to DSP.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203