CVE-2020-11175: Use After Free
u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due to improper timer handling.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009W, MSM8909W, QCS605, QM215, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA670, SDA855, SDM1000, SDM640, SDM670, SDM710, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6350, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR1120, SXR1130, SXR2130, SXR2130P
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11175?
CVE-2020-11175 is a use after free issue in the Bluetooth transport driver that occurs when a method in the object is accessed after the object has been deleted due to improper timer handling.
Which software products are affected by CVE-2020-11175?
CVE-2020-11175 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IoT, Snapdragon Industrial IoT, Snapdragon Mobile, Snapdragon Wearables, and various Qualcomm firmware versions.
What is the severity of CVE-2020-11175?
The severity of CVE-2020-11175 is high, with a CVSS score of 7.8.
Where can I find more information about CVE-2020-11175?
More information about CVE-2020-11175 can be found on the Qualcomm Product Security Bulletin for November 2020 and the Android Security Bulletin for November 2020.
How can I mitigate the vulnerability CVE-2020-11175?
To mitigate the CVE-2020-11175 vulnerability, it is recommended to apply the necessary software updates provided by the affected vendors.