Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while deinitializing a HDCP session.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Memory corruption while parsing clock configuration data for a specific hardware type.
Memory corruption while processing a config call from userspace.
Memory corruption while handling sensor utility operations.
Memory corruption while accessing a synchronization object during concurrent operations.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Cryptographic issue may occur while encrypting license data.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Transient DOS while parsing video packets received from the video firmware.
Information disclosure while processing a firmware event.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while processing a frame request from user.
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Transient DOS when processing target power rate tables during channel configuration.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Transient DOS may occur while parsing SSID in action frames.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Transient DOS may occur while parsing extended IE in beacon.
Information disclosure while creating MQ channels.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.