Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Memory Corruption when retrieving output buffer with insufficient size validation.
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Cryptographic issue while copying data to a destination buffer without validating its size.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory corruption while preprocessing IOCTL request in JPEG driver.
Memory corruption while processing a frame request from user.
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
Memory corruption while using alignments for memory allocation.
Memory Corruption when adding user-supplied data without checking available buffer space.
Memory Corruption when processing invalid user address with nonstandard buffer address.
Memory Corruption when accessing trusted execution environment without proper privilege check.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS when MAC configures config id greater than supported maximum value.
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resour…
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.