Security Vulnerabilities
- CVEs Published In March 2025
Memory corruption in display driver while detaching a device.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know.
This issue affects Apache StreamPipes: through 0.95.1.
Users are recommended to upgrade to version 0.97.0 which fixes the issue.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Information disclosure while deriving keys for a session for any Widevine use case.