Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during PlayReady APP usecase while processing TA commands.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Transient DOS while processing the EHT operation IE in the received beacon frame.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Memory corruption while handling file descriptor during listener registration/de-registration.
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption while handling session errors from firmware.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption during GNSS HAL process initialization.