Total
100
Critical
5
High
72
Medium
23
CISA KEV
2
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
information disclosure while invoking calibration data from user space to update firmware size.
Memory corruption while performing private key encryption in trusted application.
Memory corruption while processing specific files in Powerline Communication Firmware.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption while submitting blob data to kernel space though IOCTL.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing video packets received from video firmware.
Memory corruption while processing I2C settings in Camera driver.
Memory corruption may occur while processing voice call registration with user.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Transient DOS may occur while parsing SSID in action frames.
Information disclosure while creating MQ channels.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while processing command in Glink linux.
Information disclosure while deriving keys for a session for any Widevine use case.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure during audio playback.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Transient DOS while loading the TA ELF file.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when the channel ID passed by user is not validated and further used.
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Memory corruption when there is failed unmap operation in GPU.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption in SPS Application while requesting for public key in sorter TA.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption in Core Services while executing the command for removing a single event listener.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Memory corruption in Core while processing control functions.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in HLOS while running playready use-case.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory corruption in HLOS while invoking IOCTL calls from user-space.
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory Corruption in camera while installing a fd for a particular DMA buffer.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Cryptographic issue in HLOS during key management.
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
Memory corruption in TZ Secure OS while loading an app ELF.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Transient DOS in WLAN Firmware while parsing rsn ies.
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Memory corruption in WLAN HAL while parsing WMI command parameters.
Memory corruption in WLAN HAL while handling command through WMI interfaces.
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Memory corruption in Audio during playback session with audio effects enabled.
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
Transient DOS in WLAN Firmware while processing frames with missing header fields.
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Information disclosure in Kernel due to indirect branch misprediction.