Total
100
Critical
1
High
72
Medium
27
CISA KEV
0
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Memory corruption while calculating offset from partition start point.
Memory corruption when calculating oversized partition sizes without proper checks.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while processing a secure logging command in the trusted application.
Cryptographic issue may occur while encrypting license data.
Memory corruption while deinitializing a HDCP session.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Memory corruption while processing large input data from a remote source via a communication interface.
Information disclosure while processing message from client with invalid payload.
Memory corruption when triggering a subsystem crash with an out-of-range identifier.
Memory corruption while processing client message during device management.
Memory corruption while performing encryption and decryption commands.
Information disclosure while registering commands from clients with diag through diagHal.
Memory corruption while processing control commands in the virtual memory management interface.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption while handling repeated memory unmap requests from guest VM.
Memory corruption while processing data sent by FE driver.
Memory corruption while processing message in guest VM.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
information disclosure while invoking calibration data from user space to update firmware size.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while performing private key encryption in trusted application.
Information disclosure while processing a packet at EAVB BE side with invalid header length.
Information disclosure while capturing logs as eSE debug messages are logged.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS while handling beacon frames with invalid IE header length.
Memory corruption while processing video packets received from video firmware.
Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host.
Memory corruption while copying the result to the transmission queue in EMAC.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while retrieving the CBOR data from TA.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption while operating the mailbox in Automotive.
Transient DOS while processing the EHT operation IE in the received beacon frame.
Memory corruption may occur while processing voice call registration with user.
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption during the FRS UDS generation process.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while reading secure file.
Memory corruption while sound model registration for voice activation with audio kernel driver.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Memory corruption while processing message content in eAVB.
Memory corruption while transmitting packet mapping information with invalid header payload size.
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Information disclosure may be there when a guest VM is connected.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption may occur due top improper access control in HAB process.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Information disclosure while creating MQ channels.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
Memory corruption while processing input message passed from FE driver.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Memory corruption may occur while processing message from frontend during allocation.
Transient DOS may occur while processing the country IE.
Memory corruption in display driver while detaching a device.
Memory corruption may occur while accessing a variable during extended back to back tests.
Memory corruption may occur during communication between primary and guest VM.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption may occur due to improper input validation in clock device.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
Information disclosure while deriving keys for a session for any Widevine use case.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption while reading CPU state data during guest VM suspend.
Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure while processing IO control commands.
Information disclosure during audio playback.
Information disclosure while processing information on firmware image during core initialization.
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.