CVE-2020-3696: Use After Free
u'Use after free while installing new security rule in ipcrtr as old one is deleted and this rule could still be in use for checking security permission for particular process' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8996AU, QCA4531, QCA6574AU, QCA9531, QCM2150, QCS605, SDM429W, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-3696?
CVE-2020-3696 is a vulnerability that allows for use after free while installing new security rules in ipcrtr even when the old rule is deleted.
Which Qualcomm products are affected by CVE-2020-3696?
Qualcomm Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and some firmware versions of Google Android and Qualcomm chipsets are affected.
What is the severity of CVE-2020-3696?
The severity of CVE-2020-3696 is high, with a severity value of 7.8.
How can I fix CVE-2020-3696?
To fix CVE-2020-3696, it is recommended to apply the necessary security patches provided by Qualcomm.
Where can I find more information about CVE-2020-3696?
You can find more information about CVE-2020-3696 in the October 2020 security bulletin published by Qualcomm.