| Transient DOS while parsing frame during channel usage. CVE-2026-25294 | Severity high |
| Memory Corruption when validating large data buffers from external sources using addition to check buffer length. CVE-2026-25290 | Severity high |
| Information Disclosure when a pointer is reused after being deallocated. CVE-2026-25284 | Severity high |
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. CVE-2026-25283 | Severity high |
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. CVE-2026-25282 | Severity high |
| Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. CVE-2026-25281 | Severity high |
| Memory corruption when processing escape handling flow with insufficient user buffer sizes. CVE-2026-25280 | Severity high |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. CVE-2026-25275 | Severity high |
| Memory corruption while processing rear sensor IOCTL calls. CVE-2026-25261 | Severity high |
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. CVE-2026-24081 | Severity high |
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and… CVE-2026-24075 | Severity high |
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. CVE-2026-24074 | Severity high |
| Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. CVE-2026-24073 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. CVE-2025-59617 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. CVE-2025-59616 | Severity high |
| Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper… CVE-2025-59615 | Severity high |
| Memory Corruption when copying large input data exceeds normal allocation limits. CVE-2025-59607 | Severity high |
| Memory corruption when another driver calls an IOCTL with invalid input/output buffer. CVE-2025-47408 | Severity high |
| Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. CVE-2025-47407 | Severity high |
| Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. CVE-2025-47406 | Severity medium |
| Memory corruption when processing camera sensor input/output control codes with invalid output buffers. CVE-2025-47405 | Severity high |
| Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. CVE-2025-47404 | Severity high |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. CVE-2025-47403 | Severity high |
| Transient DOS when processing target power rate tables during channel configuration. CVE-2025-47401 | Severity high |
| Memory corruption occurs when a secure application is launched on a device with insufficient memory. CVE-2025-47396 | Severity high |
| Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. CVE-2025-47394 | Severity high |
| Memory corruption when decoding corrupted satellite data files with invalid signature offsets. CVE-2025-47392 | Severity high |
| Memory corruption while processing a frame request from user. CVE-2025-47391 | Severity high |
| Memory corruption while preprocessing IOCTL request in JPEG driver. CVE-2025-47390 | Severity high |
| Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. CVE-2025-47389 | Severity high |
| Memory corruption while passing pages to DSP with an unaligned starting address. CVE-2025-47388 | Severity high |
| Memory corruption while preprocessing IOCTLs in sensors. CVE-2025-47380 | Severity high |
| Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling. CVE-2025-47374 | Severity medium |
| Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. CVE-2025-47369 | Severity medium |
| Memory Corruption when multiple threads concurrently access and modify shared resources. CVE-2025-47356 | Severity high |
| Memory corruption while processing identity credential operations in the trusted application. CVE-2025-47348 | Severity high |
| Memory corruption while processing a secure logging command in the trusted application. CVE-2025-47346 | Severity high |
| Cryptographic issue may occur while encrypting license data. CVE-2025-47345 | Severity high |
| Memory corruption while handling sensor utility operations. CVE-2025-47344 | Severity medium |
| Memory corruption while processing a video session to set video parameters. CVE-2025-47343 | Severity high |
| Memory corruption while deinitializing a HDCP session. CVE-2025-47339 | Severity high |
| Memory corruption while accessing a synchronization object during concurrent operations. CVE-2025-47337 | Severity medium |
| Memory corruption while performing sensor register read operations. CVE-2025-47336 | Severity medium |
| Memory corruption while parsing clock configuration data for a specific hardware type. CVE-2025-47335 | Severity medium |
| Memory corruption while processing shared command buffer packet between camera userspace and kernel. CVE-2025-47334 | Severity medium |
| Memory corruption while handling buffer mapping operations in the cryptographic driver. CVE-2025-47333 | Severity medium |
| Memory corruption while processing a config call from userspace. CVE-2025-47332 | Severity medium |
| Information disclosure while processing a firmware event. CVE-2025-47331 | Severity medium |
| Transient DOS while parsing video packets received from the video firmware. CVE-2025-47330 | Severity medium |
| Memory corruption while routing GPR packets between user and root when handling large data packet. CVE-2025-47323 | Severity high |
| Information disclosure when Video engine escape input data is less than expected minimum size. CVE-2025-27036 | Severity medium |
| Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. CVE-2025-21488 | Severity high |
| Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the… CVE-2025-21487 | Severity high |
| Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. CVE-2025-21484 | Severity high |
| Cryptographic issue while performing RSA PKCS padding decoding. CVE-2025-21482 | Severity high |