Memory corruption while processing service requests.
Memory Corruption when executing system service routines due to improper handling of user input buffers.
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Transient DOS while parsing frame during channel usage.
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Memory corruption while processing rear sensor IOCTL calls.
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Memory Corruption when copying large input data exceeds normal allocation limits.
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
Memory corruption while using Strongbox due to buffer overflow.
Memory corruption while using Strongbox due to missing bounds check.