Security Vulnerabilities
- CVEs Published In September 2024
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Memory corruption while processing concurrent IOCTL calls.
Memory corruption when the captureRead QDCM command is invoked from user-space.
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.