Security Vulnerabilities
- CVEs Published In December 2023
Memory corruption while using the UIM diag command to get the operators name.
Memory corruption in HLOS while invoking IOCTL calls from user-space.
Memory corruption while sending SMS from AP firmware.
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
Memory corruption while loading an ELF segment in TEE Kernel.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.