CVE-2020-11156: Input Validation
u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer device.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in QCA6390, QCN7605, QCS404, SA415M, SA515M, SC8180X, SDX55, SM8250
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-11156.
What is the severity rating of CVE-2020-11156?
CVE-2020-11156 has a severity rating of 8.1 (High).
Which software and devices are affected by CVE-2020-11156?
CVE-2020-11156 affects Google Android, Qualcomm Qca6390 Firmware, Qualcomm Qcs404 Firmware, Qualcomm Sa415m Firmware, Qualcomm Sa515m Firmware, Qualcomm Sc8180x Firmware, Qualcomm Sdx55 Firmware, and Qualcomm Sm8250 Firmware.
What is the description of CVE-2020-11156?
CVE-2020-11156 is a buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer device.
How can I fix CVE-2020-11156?
To fix CVE-2020-11156, it is recommended to apply the patches and updates provided by Google and Qualcomm.