| Memory corruption when processing escape handling flow with insufficient user buffer sizes. CVE-2026-25280 | Severity high |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. CVE-2026-25275 | Severity high |
| Memory corruption while processing rear sensor IOCTL calls. CVE-2026-25261 | Severity high |
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and… CVE-2026-24075 | Severity high |
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. CVE-2026-24074 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. CVE-2025-59617 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. CVE-2025-59616 | Severity high |
| Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper… CVE-2025-59615 | Severity high |
| Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. CVE-2025-47406 | Severity medium |
| Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. CVE-2025-47404 | Severity high |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. CVE-2025-47403 | Severity high |
| Transient DOS when processing target power rate tables during channel configuration. CVE-2025-47401 | Severity high |
| Memory corruption when decoding corrupted satellite data files with invalid signature offsets. CVE-2025-47392 | Severity high |
| Memory corruption while processing a frame request from user. CVE-2025-47391 | Severity high |
| Memory corruption while preprocessing IOCTL request in JPEG driver. CVE-2025-47390 | Severity high |
| Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. CVE-2025-47389 | Severity high |
| Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. CVE-2025-47369 | Severity medium |
| Memory corruption while processing identity credential operations in the trusted application. CVE-2025-47348 | Severity high |
| Memory corruption while processing a secure logging command in the trusted application. CVE-2025-47346 | Severity high |
| Cryptographic issue may occur while encrypting license data. CVE-2025-47345 | Severity high |
| Memory corruption while handling sensor utility operations. CVE-2025-47344 | Severity medium |
| Memory corruption while processing a video session to set video parameters. CVE-2025-47343 | Severity high |
| Memory corruption while deinitializing a HDCP session. CVE-2025-47339 | Severity high |
| Memory corruption while accessing a synchronization object during concurrent operations. CVE-2025-47337 | Severity medium |
| Memory corruption while parsing clock configuration data for a specific hardware type. CVE-2025-47335 | Severity medium |
| Memory corruption while processing shared command buffer packet between camera userspace and kernel. CVE-2025-47334 | Severity medium |
| Memory corruption while handling buffer mapping operations in the cryptographic driver. CVE-2025-47333 | Severity medium |
| Information disclosure while processing a firmware event. CVE-2025-47331 | Severity medium |
| Transient DOS while parsing video packets received from the video firmware. CVE-2025-47330 | Severity medium |
| Memory corruption while routing GPR packets between user and root when handling large data packet. CVE-2025-47323 | Severity high |
| Information disclosure when Video engine escape input data is less than expected minimum size. CVE-2025-27036 | Severity medium |
| Information disclosure while running video usecase having rogue firmware. CVE-2025-27033 | Severity medium |
| Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the… CVE-2025-21487 | Severity high |
| Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. CVE-2025-21484 | Severity high |