HIGH

CVE-2020-11261

Qualcomm Apq8009 Firmware 2021-06-09 CVSS v3.1
CVSS
7.8
KEV

Description

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Summary dbcve.org

Memory corruption vulnerability in Qualcomm Snapdragon chipsets where an improper validation check fails to return an error when a user application requests an excessively large memory allocation. This allows a malicious or faulty application to trigger memory corruption by requesting unreasonable memory sizes.

Mitigation

Apply firmware updates from device manufacturers incorporating Qualcomm's patch for this vulnerability. Until the update is available, monitor application memory requests and consider application sandboxing to limit memory allocation capabilities.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write
CWE-20 Improper Input Validation

EPSS Score

1.6%
Probability of exploitation in next 30 days
74.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE