CVE-2020-3610: Use After Free
Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as there is no refcount taken for this object in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3610?
CVE-2020-3610 is classified as a high severity vulnerability due to the potential for exploitation via double free of the drawobj.
How do I fix CVE-2020-3610?
To mitigate CVE-2020-3610, ensure that your Qualcomm firmware is updated to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-3610?
CVE-2020-3610 affects a range of Qualcomm chips including Snapdragon series used in various devices, particularly those with firmware versions that have not implemented the necessary fixes.
What is the impact of exploiting CVE-2020-3610?
Exploitation of CVE-2020-3610 could potentially allow an attacker to gain control over the affected system through memory corruption.
Is there a known exploit for CVE-2020-3610?
As of now, there are no publicly available exploits specifically targeting CVE-2020-3610.