Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Memory corruption while handling session errors from firmware.
Transient DOS while processing the CU information from RNR IE.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing GPU commands.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption while allocating memory in HGSL driver.
Memory corruption while processing IOCTL call to set metainfo.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Transient DOS while processing TID-to-link mapping IE elements.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when keymaster operation imports a shared key.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.