Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while allocating buffers in DSP service.
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
Memory corruption while processing memory map or unmap IOCTL operations simultaneously.
Memory corruption while processing IOCTL calls to unmap the buffers.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption while processing user buffers.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Memory corruption while processing IPA statistics, when there are no active clients registered.
Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
Memory corruption while processing user packets to generate page faults.
Memory corruption while processing an IOCTL command with an arbitrary address.
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
Memory corruption while processing packet data with exceedingly large packet.
Page 1+ Next →