CVE-2020-11146: Out-of-bounds Read
Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11146?
CVE-2020-11146 has a severity rating of high due to the potential for denial of service and data corruption.
How do I fix CVE-2020-11146?
To fix CVE-2020-11146, apply the latest patches and firmware updates provided by Qualcomm and your device manufacturer.
What devices are affected by CVE-2020-11146?
CVE-2020-11146 affects a wide range of Qualcomm Snapdragon products, including those used in mobile and IoT devices.
What happens if CVE-2020-11146 is exploited?
If exploited, CVE-2020-11146 could allow an attacker to perform out-of-bounds write operations resulting in system instability.
Is CVE-2020-11146 fixable by end users?
Yes, end users can mitigate CVE-2020-11146 by ensuring that their device is updated with the latest software patches.