CVE-2020-11257: Buffer Overflow
Memory corruption due to lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and Networking
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11257?
CVE-2020-11257 is a vulnerability that allows memory corruption due to the lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and Networking.
How severe is CVE-2020-11257?
CVE-2020-11257 has a severity rating of 8.8, which is considered high.
What software is affected by CVE-2020-11257?
Qualcomm Ar7420 Firmware, Qualcomm Ar9580 Firmware, Qualcomm Csr8811 Firmware, Qualcomm Ipq4019 Firmware, Qualcomm Ipq4028 Firmware, Qualcomm Qca4024 Firmware, Qualcomm Qca7500 Firmware, Qualcomm Qca7520 Firmware, Qualcomm Qca7550 Firmware, Qualcomm Qca9880 Firmware, Qualcomm Qca9886 Firmware, Qualcomm Qca9888 Firmware, Qualcomm Qca9889 Firmware, Qualcomm Qcn3018 Firmware, Qualcomm Qfe1922 Firmware, Qualcomm Qfe1952 Firmware, and Google Android running on Qualcomm chipsets are affected by CVE-2020-11257.
How is CVE-2020-11257 fixed?
To fix CVE-2020-11257, users should apply the security patch provided by Qualcomm. More information can be found in the official Qualcomm January 2021 Bulletin.
What is the CWE of CVE-2020-11257?
CVE-2020-11257 is classified as CWE-119, which is a weakness related to improper restriction of operations within the bounds of a memory buffer.