Total
100
Critical
1
High
76
Medium
23
CISA KEV
1
Memory corruption while using alignments for memory allocation.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption while processing a GP command response.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while processing specific files in Powerline Communication Firmware.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
Information disclosure may occur while processing goodbye RTCP packet from network.
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
Memory corruption may occur while processing the OIS packet parser.
Memory corruption while handling test pattern generator IOCTL command.
Memory corruption while processing I2C settings in Camera driver.
Memory corruption while processing IOCTL command to handle buffers associated with a session.
Memory corruption may occur while processing voice call registration with user.
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption while processing an IOCTL call to set mixer controls.
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
Memory corruption while sound model registration for voice activation with audio kernel driver.
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
Memory corruption while prociesing command buffer buffer in OPE module.
Memory corruption Camera kernel when large number of devices are attached through userspace.
Memory corruption during array access in Camera kernel due to invalid index from invalid command data.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
Memory corruption while encoding JPEG format.
Memory corruption during concurrent buffer access due to modification of the reference count.
Memory corruption when blob structure is modified by user-space after kernel verification.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
Information disclosure while creating MQ channels.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Memory corruption while handling file descriptor during listener registration/de-registration.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Transient DOS may occur while processing the country IE.
Memory corruption in display driver while detaching a device.
Memory corruption may occur while accessing a variable during extended back to back tests.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while processing command in Glink linux.
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
Memory corruption while processing camera use case IOCTL call.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Memory corruption while power-up or power-down sequence of the camera sensor.
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
Memory corruption while handling IOCTL call from user-space to set latency level.
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure while processing IO control commands.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
Memory corruption while station LL statistic handling.
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption while processing the update SIM PB records request.
memory corruption when WiFi display APIs are invoked with large random inputs.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
Memory corruption when user provides data for FM HCI command control operations.