CVE-2020-3622: Input Validation
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3622?
CVE-2020-3622 is categorized as a high severity vulnerability due to the potential for memory corruption.
How do I fix CVE-2020-3622?
To fix CVE-2020-3622, update the affected Snapdragon firmware or software to the latest version provided by Qualcomm.
Which devices are affected by CVE-2020-3622?
CVE-2020-3622 affects various Qualcomm Snapdragon devices, including those running Android and other Qualcomm-based products.
What is the impact of exploiting CVE-2020-3622?
Exploiting CVE-2020-3622 may lead to memory corruption, resulting in potential crashes or unauthorized access to system resources.
What causes CVE-2020-3622?
CVE-2020-3622 is caused by insufficient validation of NULL termination in channel name strings read from shared memory.