Medium
CVSS: 5.5
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
High
CVSS: 7.5
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
High
CVSS: 8.4
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image…
High
CVSS: 7.8
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
High
CVSS: 7.8
Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.
High
CVSS: 7.8
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
High
CVSS: 7.8
Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.
High
CVSS: 7.8
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
High
CVSS: 7.8
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
High
CVSS: 7.8
Memory corruption when IOCTL call is invoked from user-space to read board data.
High
CVSS: 7.5
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
Medium
CVSS: 6.1
information disclosure while invoking the mailbox read API.
Medium
CVSS: 6.1
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Medium
CVSS: 6.8
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Medium
CVSS: 6.7
Memory corruption while processing frame command IOCTL calls.
Medium
CVSS: 6.7
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
Medium
CVSS: 6.7
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
Medium
CVSS: 6.6
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
High
CVSS: 8.4
Memory corruption while processing IPA statistics, when there are no active clients registered.