First published: Mon Aug 03 2020(Updated: )
u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ5018, IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCN7605, QCS404, QCS405, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Ipq5018 Firmware | ||
Qualcomm Ipq5018 | ||
Google Android | ||
Qualcomm Ipq6018 | ||
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Nicobar | ||
Qualcomm Qca6390 Firmware | ||
Qualcomm Qca6390 | ||
Google Android | ||
Google Android | ||
Qualcomm Qcs404 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Qualcomm Sa415m Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sc8180x Firmware | ||
Qualcomm Sc8180x | ||
Qualcomm Sdx55 Firmware | ||
Qualcomm Sdx55 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sm8250 Firmware | ||
Qualcomm SM8250 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3675 is a potential integer underflow vulnerability that occurs while parsing Service Info and IPv6 link-local TLVs.
CVE-2020-3675 has a severity rating of 9.8 (critical).
Qualcomm Ipq5018 Firmware, Qualcomm Ipq8074 Firmware, Qualcomm Qca6390 Firmware, Qualcomm Qcs404 Firmware, Qualcomm Qcs405 Firmware, Qualcomm Rennell Firmware, Qualcomm Sa415m Firmware, Qualcomm Sc8180x Firmware, Qualcomm Sdx55 Firmware, Qualcomm Sm8150 Firmware, Qualcomm Sm8250 Firmware, and Google Android are affected by CVE-2020-3675.
To fix CVE-2020-3675, it is recommended to apply the necessary firmware updates provided by Qualcomm and Google.
You can find more information about CVE-2020-3675 at the following references: [Link 1](https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin), [Link 2](https://source.android.com/docs/security/bulletin/2020-08-01/#asterisk), [Link 3](https://source.android.com/docs/security/bulletin/2020-08-01).