First published: Tue Sep 08 2020(Updated: )
u'Possible out of bound array write in rxdco cal utility due to lack of array bound check' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MSM8998, QCS605, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MSM8998 | ||
Qualcomm 8998 | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SD 845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD 710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm Snapdragon 850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11133.
The severity of CVE-2020-11133 is high, with a CVSS score of 7.8.
The affected software includes Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile in MSM8998, QCS605, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, and SXR1130.
It is recommended to apply the patches provided by Qualcomm and Google Android.
More information about CVE-2020-11133 can be found at the following references: [Link 1](https://source.android.com/docs/security/bulletin/2020-09-01/#asterisk), [Link 2](https://source.android.com/docs/security/bulletin/2020-09-01), [Link 3](https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin).