Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.
Memory Corruption when multiple threads simultaneously access a memory free API.
Memory corruption when calculating oversized partition sizes without proper checks.
Memory corruption while calculating offset from partition start point.
Memory corruption when accessing resources in kernel driver.
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
Cryptographic issue may occur while encrypting license data.
Memory corruption while processing a secure logging command in the trusted application.
Memory corruption while processing identity credential operations in the trusted application.
Memory Corruption when multiple threads concurrently access and modify shared resources.
Memory corruption while preprocessing IOCTLs in sensors.
Memory corruption while deinitializing a HDCP session.
Memory corruption while processing a video session to set video parameters.
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
Memory Corruption when processing IOCTLs for JPEG data without verification.
Memory corruption while copying packets received from unix clients.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Information disclosure while processing system calls with invalid parameters.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Memory corruption while processing large input data from a remote source via a communication interface.
Memory corruption while accessing a buffer during IOCTL processing.
Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
Information disclosure while processing message from client with invalid payload.
Memory corruption while processing a GP command response.
Memory corruption while processing audio streaming operations.
Memory corruption while processing request sent from GVM.
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
Memory corruption while processing client message during device management.