Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while processing identity credential operations in the trusted application.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while processing a config call from userspace.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Transient DOS may occur while parsing SSID in action frames.
Information disclosure while creating MQ channels.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Transient DOS while parsing per STA profile in ML IE.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Transient DOS while processing received beacon frame.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS while handling beacon frames with invalid IE header length.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while retrieving the CBOR data from TA.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Memory corruption while processing video packets received from video firmware.
Transient DOS may occur while processing malformed length field in SSID IEs.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.