Security Vulnerabilities
- CVEs Published In June 2023
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host
Memory corruption in Audio due to incorrect type cast during audio use-cases.
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
Memory corruption due to use after free in Core when multiple DCI clients register and deregister.
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
Memory corruption in Linux while sending DRM request.
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
Assertion occurs while processing Reconfiguration message due to improper validation
information disclosure due to cryptographic issue in Core during RPMB read request.