| Transient DOS while parsing frame during channel usage. CVE-2026-25294 | Severity high |
| Memory corruption when processing escape handling flow with insufficient user buffer sizes. CVE-2026-25280 | Severity high |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. CVE-2026-25275 | Severity high |
| Memory corruption while processing rear sensor IOCTL calls. CVE-2026-25261 | Severity high |
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. CVE-2026-24081 | Severity high |
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and… CVE-2026-24075 | Severity high |
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. CVE-2026-24074 | Severity high |
| Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. CVE-2026-24073 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. CVE-2025-59617 | Severity high |
| Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. CVE-2025-59616 | Severity high |
| Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper… CVE-2025-59615 | Severity high |
| Memory Corruption when copying large input data exceeds normal allocation limits. CVE-2025-59607 | Severity high |
| Memory corruption when another driver calls an IOCTL with invalid input/output buffer. CVE-2025-47408 | Severity high |
| Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. CVE-2025-47407 | Severity high |
| Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. CVE-2025-47406 | Severity medium |
| Memory corruption when processing camera sensor input/output control codes with invalid output buffers. CVE-2025-47405 | Severity high |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. CVE-2025-47403 | Severity high |
| Transient DOS when processing target power rate tables during channel configuration. CVE-2025-47401 | Severity high |
| Memory corruption while preprocessing IOCTL request in JPEG driver. CVE-2025-47390 | Severity high |
| Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. CVE-2025-47389 | Severity high |
| Memory Corruption when multiple threads concurrently access and modify shared resources. CVE-2025-47356 | Severity high |
| Memory corruption while processing identity credential operations in the trusted application. CVE-2025-47348 | Severity high |
| Memory corruption while processing a secure logging command in the trusted application. CVE-2025-47346 | Severity high |
| Cryptographic issue may occur while encrypting license data. CVE-2025-47345 | Severity high |
| Memory corruption while processing a video session to set video parameters. CVE-2025-47343 | Severity high |
| Memory corruption while deinitializing a HDCP session. CVE-2025-47339 | Severity high |
| Information disclosure while processing a firmware event. CVE-2025-47331 | Severity medium |
| Transient DOS while parsing video packets received from the video firmware. CVE-2025-47330 | Severity medium |
| Memory corruption while routing GPR packets between user and root when handling large data packet. CVE-2025-47323 | Severity high |
| Information disclosure when Video engine escape input data is less than expected minimum size. CVE-2025-27036 | Severity medium |
| Cryptographic issue while performing RSA PKCS padding decoding. CVE-2025-21482 | Severity high |