CVE-2018-13920: Use After Free
Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820A, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX24
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13920?
CVE-2018-13920 is rated as high severity due to the potential exploitation of a use-after-free vulnerability.
How do I fix CVE-2018-13920?
To fix CVE-2018-13920, update your device firmware to the latest version provided by Qualcomm or the device manufacturer.
What devices are affected by CVE-2018-13920?
CVE-2018-13920 affects several Qualcomm devices including MDM9206, MDM9607, and various Snapdragon models.
What impact does CVE-2018-13920 have?
The impact of CVE-2018-13920 can lead to potential system crashes or arbitrary code execution due to improper handling of hrtimers.
Who is responsible for addressing CVE-2018-13920?
Device manufacturers and Qualcomm are responsible for addressing CVE-2018-13920 by releasing firmware updates to remediate the vulnerability.