CVE-2020-11220: Race Condition
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11220?
CVE-2020-11220 has a moderate severity level due to the potential for exploitation through a time-of-check, time-of-use vulnerability.
How do I fix CVE-2020-11220?
To fix CVE-2020-11220, ensure that your device's operating system and firmware are updated to the latest versions provided by manufacturers.
What systems are affected by CVE-2020-11220?
CVE-2020-11220 affects multiple Qualcomm Snapdragon components used in Android devices.
Can CVE-2020-11220 lead to remote code execution?
Yes, CVE-2020-11220 poses a risk of remote code execution if exploited through the vulnerable pointer during storage SCM commands.
Is my Android device vulnerable to CVE-2020-11220?
Your Android device may be vulnerable to CVE-2020-11220 if it uses affected Qualcomm Snapdragon components without the latest security updates.