Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while processing identity credential operations in the trusted application.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption in display driver while detaching a device.
Information disclosure while deriving keys for a session for any Widevine use case.
Transient DOS may occur while processing the country IE.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Memory corruption while handling file descriptor during listener registration/de-registration.
Memory corruption while reading secure file.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while reading the FW response from the shared queue.
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Transient DOS while processing received beacon frame.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.