First published: Mon Jun 01 2020(Updated: )
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
qualcomm APQ8098 | ||
Qualcomm 8098 | ||
Qualcomm Kamorta | ||
qualcomm Kamorta firmware | ||
Qualcomm MSM8917 | ||
Qualcomm MSM8917 Firmware | ||
Qualcomm 8920 Firmware | ||
Qualcomm 8920 | ||
Qualcomm 8937 Firmware | ||
qualcomm MSM8937 firmware | ||
qualcomm MSM8940 firmware | ||
Qualcomm 8940 | ||
Qualcomm 8953 Firmware | ||
Qualcomm MSM8953 Firmware | ||
Qualcomm MSM8998 | ||
Qualcomm 8998 | ||
Qualcomm Nicobar | ||
Qualcomm Nicobar | ||
Qualcomm QCM2150 | ||
Qualcomm QCM2150 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm 215 | ||
Qualcomm Rennell | ||
qualcomm Rennell firmware | ||
Qualcomm Saipan Firmware | ||
Qualcomm Saipan Firmware | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
Qualcomm SDM632 | ||
Qualcomm SDM632 | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
qualcomm SM6150P firmware | ||
Qualcomm SM6150P | ||
qualcomm SM7150 firmware | ||
qualcomm SM7150 firmware | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SM8250 | ||
Qualcomm qsm8250 | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware | ||
qualcomm SXR2130P firmware | ||
Qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3676 is a vulnerability that may allow memory corruption in perfservice due to improper validation of array length taken from a user application.
CVE-2020-3676 affects Google Android, Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, and SXR2130.
CVE-2020-3676 has a severity rating of 7.8, which is considered high.
To fix CVE-2020-3676, it is recommended to apply the necessary security patches provided by Google or Qualcomm.
You can find more information about CVE-2020-3676 in the official Android security bulletin for June 2020 and the Qualcomm product security bulletins for June 2020.