First published: Thu Apr 16 2020(Updated: )
Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MSM8998 | ||
Qualcomm 8998 | ||
Qualcomm QCA6390 Firmware | ||
Qualcomm QCA6390 Firmware | ||
Qualcomm SC7180P Firmware | ||
Qualcomm SC7180 | ||
qualcomm SC8180X firmware | ||
Qualcomm SC8180X | ||
Qualcomm Snapdragon 850 Firmware | ||
Qualcomm SD850 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3653 is considered a high severity vulnerability due to the potential for buffer over-reads.
To fix CVE-2020-3653, update your Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2020-3653 affects devices using Qualcomm MSM8998, QCA6390, SC7180, SC8180X, and SDM850 firmware.
A buffer over-read occurs when a program reads more data than it should, potentially exposing sensitive information.
CVE-2020-3653 could potentially be exploited remotely if an attacker can send vulnerable input to the device.