CVE-2024-45553
Published Jan 6, 2025Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specif…
Vendor/product archive
89 CVEs tagged to qualcomm / qamsrv1h — 2 Critical, 62 High, 25 Medium, 0 Low, 0 Unrated.
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specif…
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
information disclosure while invoking the mailbox read API.
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Transient DOS while processing TID-to-link mapping IE elements.
Memory corruption while processing graphics kernel driver request to create DMA fence.
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Memory corruption while handling user packets during VBO bind operation.
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
Information Disclosure while parsing beacon frame in STA.
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
Memory corruption when the IOCTL call is interrupted by a signal.
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
Memory corruption while playing audio file having large-sized input buffer.
Memory corruption while verifying the serialized header when the key pairs are generated.
Memory corruption in HLOS while checking for the storage type.
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
Memory corruption when multiple listeners are being registered with the same file descriptor.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.