First published: Wed Jun 09 2021(Updated: )
Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm AR7420 Firmware | ||
Qualcomm AR7420 Firmware | ||
Qualcomm AR9580 | ||
Qualcomm AR9580 | ||
Qualcomm CSR8811 A12 Firmware | ||
Qualcomm CSR8811 Firmware | ||
Qualcomm IPQ4018 Firmware | ||
Qualcomm IPQ4018 Firmware | ||
Qualcomm IPQ4019 | ||
Qualcomm IPQ4019 Firmware | ||
Qualcomm IPQ4028 Firmware | ||
Qualcomm IPQ4028 Firmware | ||
Qualcomm IPQ4029 Firmware | ||
Qualcomm IPQ4029 Firmware | ||
Qualcomm QCA10901 Firmware | ||
Qualcomm QCA10901 Firmware | ||
Qualcomm QCA-4024 Firmware | ||
Qualcomm QCA-4024 Firmware | ||
Qualcomm QCA7500 Firmware | ||
Qualcomm QCA7500 Firmware | ||
Qualcomm QCA7520 Firmware | ||
Qualcomm QCA7520 Firmware | ||
Qualcomm QCA7550 Firmware | ||
Qualcomm QCA7550 Firmware | ||
Qualcomm QCA8075 Firmware | ||
Qualcomm QCA8075 Firmware | ||
Qualcomm QCA9880 | ||
Qualcomm QCA9880 | ||
Qualcomm QCA9886 Firmware | ||
Qualcomm QCA9886 Firmware | ||
Qualcomm QCA9888 Firmware | ||
Qualcomm QCA9888 Firmware | ||
Qualcomm QCA9889 Firmware | ||
Qualcomm QCA9889 Firmware | ||
Qualcomm QCA9898 Firmware | ||
Qualcomm QCA9898 Firmware | ||
Qualcomm QCA9984 Firmware | ||
qualcomm qca9984 firmware | ||
Qualcomm QCA9992 Firmware | ||
Qualcomm QCA9992 Firmware | ||
Qualcomm QCA9994 | ||
Qualcomm QCA9994 Firmware | ||
Qualcomm QCN3018 Firmware | ||
Qualcomm QCN3018 Firmware | ||
Qualcomm QFE1922 Firmware | ||
qualcomm qfe1922 Firmware | ||
qualcomm qfe1952 Firmware | ||
qualcomm qfe1952 Firmware | ||
Qualcomm WCD9340 Firmware | ||
Qualcomm WCD9340 Firmware | ||
Qualcomm WSA8810 | ||
Qualcomm WSA8810 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11266 is a vulnerability that occurs when an image address is dereferenced before validating its range, potentially causing QSEE information leakage in Snapdragon Wired Infrastructure and Networking.
The following software is affected: Qualcomm Ar7420 Firmware, Qualcomm Ar9580 Firmware, Qualcomm Csr8811 Firmware, Qualcomm Ipq4019 Firmware, Qualcomm Qca4024 Firmware, Qualcomm Qca7500 Firmware, Qualcomm Qca7520 Firmware, Qualcomm Qca7550 Firmware, Qualcomm Qcn3018 Firmware, Qualcomm Qfe1922 Firmware, Qualcomm Qfe1952 Firmware, Qualcomm Wcd9340 Firmware, Qualcomm Wsa8810 Firmware.
The severity of CVE-2020-11266 is medium with a CVSS score of 6.5.
QSEE stands for Qualcomm Secure Execution Environment, which is a trusted execution environment on Qualcomm Snapdragon processors.
You can find more information about CVE-2020-11266 on the Qualcomm Product Security Bulletin for January 2021.