CVE-2020-11148: Use After Free
Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggered and callback instance is deleted in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11148?
The severity of CVE-2020-11148 is rated as high due to the potential for exploitation through use-after-free vulnerabilities.
How do I fix CVE-2020-11148?
To fix CVE-2020-11148, apply the latest firmware updates provided by Qualcomm for your affected devices.
What are the potential impacts of CVE-2020-11148?
The potential impacts of CVE-2020-11148 include denial of service and potential remote code execution due to improper callback handling.
Which devices are affected by CVE-2020-11148?
CVE-2020-11148 affects a variety of Qualcomm Snapdragon devices across different platforms including automotive, computing, and IoT.
Is there a workaround for CVE-2020-11148?
Currently, there is no known workaround for CVE-2020-11148 other than applying the appropriate firmware updates.