CVE-2020-3676: Input Validation
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3676?
CVE-2020-3676 is a vulnerability that may allow memory corruption in perfservice due to improper validation of array length taken from a user application.
Which software products are affected by CVE-2020-3676?
CVE-2020-3676 affects Google Android, Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, and SXR2130.
What is the severity of CVE-2020-3676?
CVE-2020-3676 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2020-3676?
To fix CVE-2020-3676, it is recommended to apply the necessary security patches provided by Google or Qualcomm.
Where can I find more information about CVE-2020-3676?
You can find more information about CVE-2020-3676 in the official Android security bulletin for June 2020 and the Qualcomm product security bulletins for June 2020.