CWE
416 362
Advisory Published
Updated

CVE-2020-11152: Use After Free

First published: Thu Jan 21 2021(Updated: )

Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
qualcomm apq8009w
Qualcomm apq8017
qualcomm apq8037
qualcomm apq8052
Qualcomm APQ8053 Firmware
qualcomm apq8056
qualcomm apq8076
Qualcomm apq8096au
Qualcomm aqt1000
Qualcomm ar8031
Qualcomm csra6620
Qualcomm csra6640
Qualcomm MSM8909W
qualcomm msm8916
Qualcomm msm8917
qualcomm MSM8920
qualcomm MSM8937
qualcomm MSM8940
Qualcomm 8952
Qualcomm msm8953
Qualcomm MSM8956 Firmware
Qualcomm 8976
Qualcomm 8976
Qualcomm MSM8996AU Firmware
Qualcomm pm439
Qualcomm pm660
Qualcomm pm660a
Qualcomm pm660l
Qualcomm pm670
Qualcomm pm670a
Qualcomm pm670l
Qualcomm pm8004
Qualcomm pm8005
Qualcomm pm855
Qualcomm pm855a
Qualcomm Pm855b
Qualcomm pm855l
Qualcomm pm855p
Qualcomm pm8916
Qualcomm pm8937
Qualcomm PMI8940 Firmware
qualcomm pm8952
Qualcomm pm8953
qualcomm pm8956
Qualcomm pm8998
Qualcomm pmd9655
Qualcomm pmi632
Qualcomm pmi8937
Qualcomm pmi8952
Qualcomm pmi8998
Qualcomm pmm8996au
Qualcomm pmx24
Qualcomm pmx50
Qualcomm qat3514
Qualcomm qat3522
Qualcomm qat3550
Qualcomm qbt1000
Qualcomm qbt1500
Qualcomm qbt2000
Qualcomm qca6174a
qualcomm qca6310
qualcomm qca6320
Qualcomm qca6420
Qualcomm qca6430
Qualcomm qca6564a
qualcomm qca6564au
qualcomm qca6574a
qualcomm qca6574au
qualcomm QCA6584AU
qualcomm qca8337
Qualcomm qca9377
qualcomm qcc1110
Qualcomm QCS405 Firmware
Qualcomm qcs603
Qualcomm QCS605
Qualcomm qet4100
Qualcomm qet4101
Qualcomm qet5100
Qualcomm qet5100m
qualcomm qfe2080fc
qualcomm qfe2081fc
qualcomm qfe2082fc
Qualcomm qfe2101
Qualcomm qfe2550
qualcomm qfe3100
qualcomm qfe3440fc
Qualcomm qfe4301
Qualcomm qfe4302
Qualcomm qfe4303
Qualcomm qfe4305
Qualcomm qfe4308
Qualcomm qfe4309
Qualcomm qfe4320
Qualcomm qfe4373fc
qualcomm qfe4455fc
qualcomm qfe4465fc
qualcomm qln1035bd
Qualcomm qpa4340
Qualcomm qpa4360
Qualcomm qpa5460
Qualcomm qsw8573
Qualcomm qtc800h
Qualcomm qtc800s
Qualcomm qtc800t
Qualcomm qtc801s
Qualcomm rgr7640au
Qualcomm rsw8577
Qualcomm sd439
Qualcomm sd450
Qualcomm sd636
Qualcomm sd660
Qualcomm sd710
qualcomm sd712
Qualcomm sd835
qualcomm sd855
Qualcomm sd8cx
qualcomm SDM630
Qualcomm sdm830
Qualcomm sdr051
Qualcomm sdr052
Qualcomm sdr660
Qualcomm sdr8150
qualcomm sdw2500
Qualcomm sdw3100
Qualcomm sdx24
Qualcomm sdx50m
qualcomm smb1351
qualcomm smb1355
Qualcomm smb1358
Qualcomm smb1360
qualcomm smb1380
qualcomm smb1381
qualcomm smb1390
Qualcomm smb231
qualcomm wcd9306
Qualcomm wcd9326
Qualcomm wcd9330
qualcomm wcd9335
qualcomm wcd9340
qualcomm wcd9341
Qualcomm wcd9360
Qualcomm wcn3610
Qualcomm wcn3615
Qualcomm wcn3620
Qualcomm wcn3660b
Qualcomm wcn3680b
qualcomm wcn3950
Qualcomm Wcn3980
qualcomm wcn3990
Qualcomm wcn3998
Qualcomm wcn3999
qualcomm wgr7640
qualcomm whs9410
qualcomm wsa8810
qualcomm wsa8815
Qualcomm wtr2955
qualcomm wtr2965
qualcomm wtr3925
Qualcomm Wtr4905
qualcomm wtr5975

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2020-11152?

    CVE-2020-11152 has been classified with a medium severity rating.

  • How do I fix CVE-2020-11152?

    To fix CVE-2020-11152, apply the security patches provided by Qualcomm in their December 2020 security bulletin.

  • Which devices are affected by CVE-2020-11152?

    CVE-2020-11152 affects various Qualcomm Snapdragon chipsets used in automotive, consumer IoT, and mobile devices.

  • Can CVE-2020-11152 be exploited remotely?

    Yes, CVE-2020-11152 can potentially be exploited remotely due to its nature as a race condition in the HAL layer.

  • What types of products use the affected Qualcomm components in CVE-2020-11152?

    Products using Snapdragon Auto, Snapdragon Compute, mobile phones, and certain IoT devices are likely to be impacted by CVE-2020-11152.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203