Total
100
Critical
5
High
68
Medium
27
CISA KEV
0
Memory corruption while deinitializing a HDCP session.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Information disclosure while processing system calls with invalid parameters.
Memory corruption while processing MFC channel configuration during music playback.
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
Memory corruption while processing a GP command response.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Information disclosure may occur while processing the hypervisor log.
Transient DOS while handling command data during power control processing.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Memory corruption while selecting the PLMN from SOR failed list.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
information disclosure while invoking calibration data from user space to update firmware size.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while performing private key encryption in trusted application.
Memory corruption while processing specific files in Powerline Communication Firmware.
Transient DOS while processing an ANQP message.
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption while submitting blob data to kernel space though IOCTL.
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS while handling beacon frames with invalid IE header length.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing received beacon frame.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Transient DOS may occur while processing malformed length field in SSID IEs.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption while operating the mailbox in Automotive.
Transient DOS while processing the EHT operation IE in the received beacon frame.
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
Information disclosure may occur while processing goodbye RTCP packet from network.
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
Memory corruption while processing I2C settings in Camera driver.
Memory corruption may occur while processing voice call registration with user.
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Transient DOS may occur while parsing SSID in action frames.
Transient DOS may occur while parsing extended IE in beacon.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Information disclosure while creating MQ channels.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while processing command in Glink linux.
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
Information disclosure while deriving keys for a session for any Widevine use case.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure during audio playback.
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Memory corruption while redirecting log file to any file location with any file name.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while processing concurrent IOCTL calls.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
Memory corruption when user provides data for FM HCI command control operations.
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.