CVE-2020-11176: Critical severity Google Android vulnerability
While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11176?
CVE-2020-11176 has a high severity rating due to the potential for memory corruption and subsequent exploitation.
How do I fix CVE-2020-11176?
To fix CVE-2020-11176, apply the latest security patch provided by your device manufacturer that addresses this vulnerability.
What systems are affected by CVE-2020-11176?
CVE-2020-11176 affects various Qualcomm firmware and devices running Android, including Snapdragon Auto and Snapdragon Compute.
What are the possible consequences of exploiting CVE-2020-11176?
Exploiting CVE-2020-11176 could lead to arbitrary code execution, causing systems to become unstable or compromised.
Is there any workaround for CVE-2020-11176 while waiting for a patch?
Currently, there are no effective workarounds for CVE-2020-11176, so updating to the patched version is essential.