First published: Mon May 04 2020(Updated: )
A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MSM8909W, MSM8917, MSM8953, QCS605, QM215, SA415M, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm APQ8009W Firmware | ||
Qualcomm APQ8009W | ||
qualcomm apq8053-ac firmware | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm MSM8917 | ||
Qualcomm MSM8917 Firmware | ||
Qualcomm 8953 Firmware | ||
Qualcomm MSM8953 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm 215 | ||
Qualcomm SA415M | ||
Qualcomm sa415m firmware | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM429W | ||
qualcomm SDM429W firmware | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
Qualcomm SDM632 | ||
Qualcomm SDM632 | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3680 is classified as a high-severity vulnerability due to the potential for a race condition affecting memory mapping APIs.
To fix CVE-2020-3680, you should apply the latest firmware updates from your device manufacturer that address this vulnerability.
CVE-2020-3680 affects various Qualcomm Snapdragon platforms, including APQ8009, APQ8053, and several others.
CVE-2020-3680 impacts the memory mapping API used in Qualcomm Snapdragon systems, potentially leading to unauthorized access or system instability.
Currently, the most effective workaround for CVE-2020-3680 is to ensure your device is updated with the latest security patches from Qualcomm.