CVE-2020-3639: Out-of-bounds Read
u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8017, APQ8037, APQ8053, MDM9250, MDM9607, MDM9628, MDM9640, MDM9650, MSM8108, MSM8208, MSM8209, MSM8608, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCM4290, QCM6125, QCS410, QCS4290, QCS603, QCS605, QCS610, QCS6125, QM215, QSM8350, SA415M, SA6145P, SA6150P, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SC8180X, SC8180X+SDX55, SC8180XP, SDA429W, SDA640, SDA660, SDA670, SDA845, SDA855, SDM1000, SDM429, SDM429W, SDM439, SDM450, SDM455, SDM630, SDM632, SDM636, SDM640, SDM660, SDM670, SDM710, SDM712, SDM845, SDM850, SDX24, SDX50M, SDX55, SDX55M, SM4125, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8350, SM8350P, SXR1120, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3639?
CVE-2020-3639 has a high severity rating due to its potential for significant impact on device performance and stability.
How do I fix CVE-2020-3639?
To fix CVE-2020-3639, ensure that you update your affected Qualcomm device firmware to the latest version provided by the manufacturer.
Which devices are affected by CVE-2020-3639?
CVE-2020-3639 affects several Qualcomm Snapdragon devices including those in automotive, mobile, and IoT categories.
What type of vulnerability is CVE-2020-3639?
CVE-2020-3639 is a vulnerability related to SIP signaling compression that may lead to excessive resource usage.
Is there a workaround for CVE-2020-3639 until a patch is applied?
Currently, there is no recommended workaround for CVE-2020-3639 other than applying the firmware update as soon as it becomes available.