CVE-2020-11261
Description
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Summary dbcve.org
Memory corruption vulnerability in Qualcomm Snapdragon chipsets where an improper validation check fails to return an error when a user application requests an excessively large memory allocation. This allows a malicious or faulty application to trigger memory corruption by requesting unreasonable memory sizes.
Mitigation
Apply firmware updates from device manufacturers incorporating Qualcomm's patch for this vulnerability. Until the update is available, monitor application memory requests and consider application sandboxing to limit memory allocation capabilities.