23 known vulnerabilities · sorted by CVSS score
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption in HLOS while running playready use-case.
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption in Audio during playback with speaker protection.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Memory corruption while processing API calls to NPU with invalid input.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
Cryptographic issue while performing RSA PKCS padding decoding.
information disclosure due to cryptographic issue in Core during RPMB read request.