| Transient DOS while parsing frame during channel usage. CVE-2026-25294 | Severity high |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. CVE-2026-25275 | Severity high |
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. CVE-2026-24081 | Severity high |
| Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. CVE-2025-47404 | Severity high |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. CVE-2025-47403 | Severity high |
| Transient DOS when processing target power rate tables during channel configuration. CVE-2025-47401 | Severity high |
| Memory corruption when decoding corrupted satellite data files with invalid signature offsets. CVE-2025-47392 | Severity high |
| Memory corruption while processing a frame request from user. CVE-2025-47391 | Severity high |
| Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. CVE-2025-47389 | Severity high |
| Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. CVE-2025-47369 | Severity medium |
| Memory corruption while processing identity credential operations in the trusted application. CVE-2025-47348 | Severity high |
| Memory corruption while processing a secure logging command in the trusted application. CVE-2025-47346 | Severity high |
| Cryptographic issue may occur while encrypting license data. CVE-2025-47345 | Severity high |
| Memory corruption while handling sensor utility operations. CVE-2025-47344 | Severity medium |
| Memory corruption while deinitializing a HDCP session. CVE-2025-47339 | Severity high |
| Memory corruption while accessing a synchronization object during concurrent operations. CVE-2025-47337 | Severity medium |
| Memory corruption while parsing clock configuration data for a specific hardware type. CVE-2025-47335 | Severity medium |
| Memory corruption while processing shared command buffer packet between camera userspace and kernel. CVE-2025-47334 | Severity medium |
| Memory corruption while handling buffer mapping operations in the cryptographic driver. CVE-2025-47333 | Severity medium |
| Memory corruption while processing a config call from userspace. CVE-2025-47332 | Severity medium |
| Information disclosure while processing a firmware event. CVE-2025-47331 | Severity medium |
| Transient DOS while parsing video packets received from the video firmware. CVE-2025-47330 | Severity medium |
| Memory corruption while routing GPR packets between user and root when handling large data packet. CVE-2025-47323 | Severity high |
| Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. CVE-2025-21488 | Severity high |
| Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the… CVE-2025-21487 | Severity high |
| Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. CVE-2025-21484 | Severity high |
| Cryptographic issue while performing RSA PKCS padding decoding. CVE-2025-21482 | Severity high |