CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Memory corruption may occur in keyboard virtual device due to guest VM interaction. | 7.8 |
Haute |
||
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine. | 7.8 |
Haute |
||
Memory corruption while processing input message passed from FE driver. | 7.8 |
Haute |
||
Transient DOS may occur while processing the country IE. | 7.5 |
Haute |
||
Memory corruption in display driver while detaching a device. | 7.8 |
Haute |
||
Memory corruption may occur while accessing a variable during extended back to back tests. | 7.8 |
Haute |
||
Memory corruption may occur during communication between primary and guest VM. | 7.8 |
Haute |
||
Memory corruption may occur while validating ports and channels in Audio driver. | 7.8 |
Haute |
||
Information disclosure while deriving keys for a session for any Widevine use case. | 5.5 |
Moyen |
||
Memory corruption during management frame processing due to mismatch in T2LM info element. | 9.8 |
Critique |
||
Information disclosure while parsing the OCI IE with invalid length. | 8.2 |
Haute |
||
Memory corruption while reading CPU state data during guest VM suspend. | 7.8 |
Haute |
||
Memory corruption while parsing the ML IE due to invalid frame content. | 9.8 |
Critique |
||
Memory corruption while configuring a Hypervisor based input virtual device. | 8.8 |
Haute |
||
Memory corruption while parsing the memory map info in IOCTL calls. | 7.8 |
Haute |
||
Information disclosure while processing IO control commands. | 6.1 |
Moyen |
||
Information disclosure during audio playback. | 6.1 |
Moyen |
||
Information disclosure while processing information on firmware image during core initialization. | 6.1 |
Moyen |
||
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. | 5.5 |
Moyen |
||
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | 7.5 |
Haute |
||
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image. | 8.4 |
Haute |
||
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | 7.5 |
Haute |
||
information disclosure while invoking the mailbox read API. | 6.1 |
Moyen |
||
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | 6.1 |
Moyen |
||
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size. | 6.6 |
Moyen |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Memory corruption when multiple threads try to unregister the CVP buffer at the same time. | 6.7 |
Moyen |
||
Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | 8.4 |
Haute |
||
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. | 6.1 |
Moyen |
||
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | 6.7 |
Moyen |
||
Memory corruption while processing GPU page table switch. | 7.8 |
Haute |
||
Memory corruption while processing voice packet with arbitrary data received from ADSP. | 7.8 |
Haute |
||
Memory corruption while handling session errors from firmware. | 7.8 |
Haute |
||
Transient DOS while processing the CU information from RNR IE. | 7.5 |
Haute |
||
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. | 6.7 |
Moyen |
||
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host. | 7.5 |
Haute |
||
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. | 7.5 |
Haute |
||
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. | 7.8 |
Haute |
||
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. | 7.5 |
Haute |
||
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | 7.5 |
Haute |
||
Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | 8.4 |
Haute |
||
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. | 8.4 |
Haute |
||
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | 8.4 |
Haute |
||
Memory corruption while processing IOCTL call to set metainfo. | 8.4 |
Haute |
||
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. | 7.5 |
Haute |
||
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. | 7.5 |
Haute |
||
Transient DOS while parsing ESP IE from beacon/probe response frame. | 7.5 |
Haute |
||
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | 7.5 |
Haute |
||
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | 7.5 |
Haute |
||
Transient DOS while parsing fragments of MBSSID IE from beacon frame. | 7.5 |
Haute |
||
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | 6.2 |
Moyen |
||
Memory corruption during session sign renewal request calls in HLOS. | 7.8 |
Haute |
||
Memory corruption when keymaster operation imports a shared key. | 7.8 |
Haute |
||
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | 8.4 |
Haute |
||
Transient DOS during music playback of ALAC content. | 7.5 |
Haute |
||
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | 8.4 |
Haute |
||
Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | 7.8 |
Haute |
||
Memory corruption while processing key blob passed by the user. | 7.8 |
Haute |
||
Transient DOS while loading the TA ELF file. | 7.1 |
Haute |
||
Memory corruption while performing finish HMAC operation when context is freed by keymaster. | 8.4 |
Haute |
||
Memory corruption in Hypervisor when platform information mentioned is not aligned. | 9.3 |
Critique |
||
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | 7.8 |
Haute |
||
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. | 9.3 |
Critique |
||
Memory corruption while playing audio file having large-sized input buffer. | 9.8 |
Critique |
||
Memory corruption when the payload received from firmware is not as per the expected protocol size. | 7.8 |
Haute |
||
Memory corruption when size of buffer from previous call is used without validation or re-initialization. | 8.4 |
Haute |
||
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. | 8.4 |
Haute |
||
Memory corruption while verifying the serialized header when the key pairs are generated. | 8.4 |
Haute |
||
Memory corruption in HLOS while checking for the storage type. | 7.8 |
Haute |
||
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. | 8.4 |
Haute |
||
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | 7.8 |
Haute |
||
Memory corruption while processing finish_sign command to pass a rsp buffer. | 8.4 |
Haute |
||
Memory corruption in SPS Application while requesting for public key in sorter TA. | 8.4 |
Haute |
||
Memory corruption in Core Services while executing the command for removing a single event listener. | 9.3 |
Critique |
||
Memory corruption in Automotive Multimedia due to improper access control in HAB. | 8.4 |
Haute |
||
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | 7.8 |
Haute |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critique |
||
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. | 7.8 |
Haute |
||
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data. | 7.1 |
Haute |
||
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | 7.1 |
Haute |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critique |
||
Transient DOS in Automotive OS due to improper authentication to the secure IO calls. | 7.1 |
Haute |
||
Memory corruption in HLOS while invoking IOCTL calls from user-space. | 8.4 |
Haute |
||
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | 7.8 |
Haute |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Moyen |
||
Memory corruption while loading an ELF segment in TEE Kernel. | 8.8 |
Haute |
||
Memory Corruption in SPS Application while exporting public key in sorter TA. | 7.8 |
Haute |
||
Cryptographic issue in HLOS during key management. | 7.8 |
Haute |
||
Memory corruption in TZ Secure OS while loading an app ELF. | 8.2 |
Haute |
||
Memory Corruption in Core due to secure memory access by user while loading modem image. | 8.4 |
Haute |
||
Memory corruption in Automotive Display while destroying the image handle created using connected display driver. | 8.4 |
Haute |
||
Memory Corruption in HLOS while registering for key provisioning notify. | 8.4 |
Haute |
||
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | 7.8 |
Haute |
||
Weak configuration in Automotive while VM is processing a listener request from TEE. | 8.2 |
Haute |
||
Improper Access to the VM resource manager can lead to Memory Corruption. | 8.7 |
Haute |
||
Memory Corruption in Core Platform while printing the response buffer in log. | 7.8 |
Haute |
||
Memory corruption in Core Platform while printing the response buffer in log. | 7.8 |
Haute |
||
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use. | 7.7 |
Haute |
||
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. | 9.3 |
Critique |
||
Memory corruption due to untrusted pointer dereference in automotive during system call. | 9.1 |
Critique |
||
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | 7.1 |
Haute |
||
Memory corruption in Automotive GPU while querying a gsl memory node. | 8.4 |
Haute |
||
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | 6.2 |
Moyen |
||
Memory corruption due to improper access control in kernel while processing a mapping request from root process. | 7.8 |
Haute |
||
Information disclosure in Kernel due to indirect branch misprediction. | 7.1 |
Haute |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
Haute |
||
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed. | 8.4 |
Haute |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
Haute |
||
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. | 7.3 |
Haute |
||
Memory corruption in HAB Memory management due to broad system privileges via physical address. | 8.4 |
Haute |
||
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key. | 7.8 |
Haute |
||
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | 9.3 |
Critique |
||
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback. | 8.4 |
Haute |
||
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | 9.3 |
Critique |
||
Memory corruption due to double free in core while initializing the encryption key. | 9.3 |
Critique |
||
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. | 7.8 |
Haute |
||
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | 9.3 |
Critique |
||
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. | 7.8 |
Haute |
||
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory. | 9.3 |
Critique |
||
Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file. | 6 |
Moyen |
||
Memory corruption due to stack-based buffer overflow in Core | 8.4 |
Haute |
||
Information disclosure due to buffer overread in Core | 6.8 |
Moyen |
||
Information disclosure due to buffer overread in Core | 6.8 |
Moyen |
||
Memory corruption in core due to stack-based buffer overflow | 8.4 |
Haute |
||
Memory corruption in Core due to stack-based buffer overflow. | 8.4 |
Haute |
||
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer. | 9.3 |
Critique |
||
Memory corruption in Automotive due to improper input validation. | 8.2 |
Haute |
||
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping. | 8.1 |
Haute |
||
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caches in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 8.4 |
Haute |
||
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto | 8.4 |
Haute |
||
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 7.8 |
Haute |
||
Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 8.4 |
Haute |
||
Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile | 7.1 |
Haute |
||
Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto | 8.4 |
Haute |
||
Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto | 8.4 |
Haute |
||
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto | 6.2 |
Moyen |
||
Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto | 8.4 |
Haute |
||
Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto | 8.4 |
Haute |
||
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 6.2 |
Moyen |
||
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | 8.4 |
Haute |
||
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | 9.3 |
Critique |
||
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 7.3 |
Haute |
||
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | 7.8 |
Haute |
||
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | 9.3 |
Critique |
||
Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto | 7.8 |
Haute |
||
Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto | 8.4 |
Haute |
||
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile | 7.1 |
Haute |
||
Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile | 8.4 |
Haute |
||
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | 7.8 |
Haute |
||
Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 7.8 |
Haute |
||
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 7.8 |
Haute |