CVE-2020-11298: Race Condition
While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memory buffers used by HLOS Invoke Call to secure kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11298?
The severity of CVE-2020-11298 is classified as high due to potential unauthorized access and modification of shared memory buffers.
How do I fix CVE-2020-11298?
To fix CVE-2020-11298, update your Qualcomm firmware to the latest version provided by the vendor.
What products are affected by CVE-2020-11298?
CVE-2020-11298 affects various Qualcomm products including certain firmware for Snapdragon Auto and Snapdragon Compute devices.
What could exploit CVE-2020-11298?
Exploitation of CVE-2020-11298 could allow non-secure clients to manipulate permissions of memory buffers, leading to security breaches.
Is there a patch available for CVE-2020-11298?
Yes, Qualcomm has released patches for CVE-2020-11298 as part of their security updates.