Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Transient DOS when processing target power rate tables during channel configuration.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
Memory Corruption when handling power management requests with improperly sized input/output buffers.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connect…
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Memory Corruption when retrieving output buffer with insufficient size validation.
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Cryptographic issue while copying data to a destination buffer without validating its size.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while preprocessing IOCTL request in JPEG driver.
Memory Corruption when processing invalid user address with nonstandard buffer address.
Memory Corruption when accessing trusted execution environment without proper privilege check.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS when MAC configures config id greater than supported maximum value.
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
Transient DOS when processing a received frame with an excessively large authentication information element.