CVE-2020-11120: Use After Free
u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may not be valid and will lead to use after free scenario' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, APQ8098, Bitra, Kamorta, MSM8917, MSM8953, MSM8998, QCM2150, QCS405, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM632, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-11120.
What is the severity rating of CVE-2020-11120?
CVE-2020-11120 has a severity rating of 7.8 (High).
Which software products are affected by CVE-2020-11120?
CVE-2020-11120 affects the following software products: Google Android, Qualcomm Apq8096au Firmware, Qualcomm MSM8917 Firmware, Qualcomm Sdm439 Firmware, Qualcomm Qcs405 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Qm215 Firmware, Qualcomm Rennell Firmware, Qualcomm Saipan Firmware, Qualcomm Sxr2130 Firmware.
What is the description of CVE-2020-11120?
CVE-2020-11120 is a vulnerability where the calling thread may free the data buffer pointer that was passed to the callback, leading to a use after free scenario.
Are Qualcomm Apq8096au and Qualcomm MSM8998 vulnerable to CVE-2020-11120?
No, Qualcomm Apq8096au and Qualcomm MSM8998 are not vulnerable to CVE-2020-11120.