CVE-2020-11215: Critical severity Google Android vulnerability
An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11215?
The severity of CVE-2020-11215 is considered high due to the potential for an out of bounds read that could lead to information disclosure or system instability.
How do I fix CVE-2020-11215?
To fix CVE-2020-11215, update the affected software to the latest version provided by the vendor to ensure that the vulnerability is patched.
Which devices are affected by CVE-2020-11215?
CVE-2020-11215 affects multiple Qualcomm Snapdragon products and devices running Google Android versions that utilize these chips.
What is the exploitability of CVE-2020-11215?
CVE-2020-11215 may be exploited remotely if attackers have access to VSA attributes that lack proper length checks.
What types of vulnerabilities does CVE-2020-11215 represent?
CVE-2020-11215 represents an out of bounds read vulnerability due to insufficient checks on the minimum required length of attributes.