Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
Memory corruption while transmitting packet mapping information with invalid header payload size.
Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Transient DOS may occur while parsing extended IE in beacon.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Memory corruption while processing escape code in API.
Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.
Memory corruption may occur due top improper access control in HAB process.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
Information disclosure while creating MQ channels.
Memory corruption while processing IOCTL calls to add route entry in the HW.
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially l…
Memory corruption while processing IOCTL calls.
Memory corruption while handling file descriptor during listener registration/de-registration.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag …
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.