Total
100
Critical
2
High
67
Medium
31
CISA KEV
1
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory corruption while using alignments for memory allocation.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during video playback when video session open fails with time out error.
Memory corruption while processing a GP command response.
Information disclosure while registering commands from clients with diag through diagHal.
Memory corruption while invoking remote procedure IOCTL calls.
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
information disclosure while invoking calibration data from user space to update firmware size.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Memory corruption while processing commands from A2dp sink command queue.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing data packets in diag received from Unix clients.
Memory corruption while processing video packets received from video firmware.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
Information disclosure may occur while processing goodbye RTCP packet from network.
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
Memory corruption may occur while processing voice call registration with user.
Memory corruption while reading the FW response from the shared queue.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption during concurrent access to server info object due to incorrect reference count update.
Memory corruption during concurrent access to server info object due to unprotected critical field.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
Information disclosure while creating MQ channels.
Memory corruption while processing IOCTL calls to add route entry in the HW.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
Memory corruption while handling file descriptor during listener registration/de-registration.
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
There may be information disclosure during memory re-allocation in TZ Secure OS.
Memory corruption while calling the NPU driver APIs concurrently.
Memory corruption may occur while validating ports and channels in Audio driver.
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Memory corruption while processing command in Glink linux.
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Memory corruption while parsing the memory map info in IOCTL calls.
Information disclosure while processing IO control commands.
Information disclosure during audio playback.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Memory corruption while processing API calls to NPU with invalid input.
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while handling session errors from firmware.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption during the network scan request.
Memory corruption while processing concurrent IOCTL calls.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Memory corruption when user provides data for FM HCI command control operations.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption when Alternative Frequency offset value is set to 255.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Transient DOS during music playback of ALAC content.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Information disclosure in Video while parsing mp2 clip with invalid section length.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.