Total
100
Critical
2
High
70
Medium
28
CISA KEV
1
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption while processing a frame request from user.
Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while performing encryption and decryption commands.
Information disclosure while registering commands from clients with diag through diagHal.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
Memory corruption while selecting the PLMN from SOR failed list.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory corruption while performing private key encryption in trusted application.
Transient DOS while creating NDP instance.
Memory corruption while processing specific files in Powerline Communication Firmware.
Transient DOS while processing an ANQP message.
Transient DOS while processing a frame with malformed shared-key descriptor.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Memory corruption while processing commands from A2dp sink command queue.
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
Information disclosure while capturing logs as eSE debug messages are logged.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption when programming registers through virtual CDM.
Memory corruption while submitting blob data to kernel space though IOCTL.
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
Information disclosure may occur while processing goodbye RTCP packet from network.
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
Memory corruption may occur while processing the OIS packet parser.
Memory corruption while processing I2C settings in Camera driver.
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
Transient DOS may occur while parsing SSID in action frames.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
Information disclosure while creating MQ channels.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
Memory corruption while processing IOCTL calls.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption during GNSS HAL process initialization.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
memory corruption when WiFi display APIs are invoked with large random inputs.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Information disclosure while sending implicit broadcast containing APP launch information.
Memory corruption while processing user packets to generate page faults.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
Cryptographic issue while parsing RSA keys in COBR format.
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Memory corruption during session sign renewal request calls in HLOS.
Memory corruption when keymaster operation imports a shared key.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Transient DOS during music playback of ALAC content.
Memory corruption while handling user packets during VBO bind operation.