Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while processing a malformed license file during reboot.
Cryptographic issue while performing RSA PKCS padding decoding.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS while loading the TA ELF file.
Memory corruption while processing key blob passed by the user.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Memory corruption in Core while processing control functions.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
Memory corruption in HLOS while running playready use-case.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.