CVE-2020-11152: Use After Free
Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11152?
CVE-2020-11152 has been classified with a medium severity rating.
How do I fix CVE-2020-11152?
To fix CVE-2020-11152, apply the security patches provided by Qualcomm in their December 2020 security bulletin.
Which devices are affected by CVE-2020-11152?
CVE-2020-11152 affects various Qualcomm Snapdragon chipsets used in automotive, consumer IoT, and mobile devices.
Can CVE-2020-11152 be exploited remotely?
Yes, CVE-2020-11152 can potentially be exploited remotely due to its nature as a race condition in the HAL layer.
What types of products use the affected Qualcomm components in CVE-2020-11152?
Products using Snapdragon Auto, Snapdragon Compute, mobile phones, and certain IoT devices are likely to be impacted by CVE-2020-11152.