CVE-2020-11124
u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCS404, QCS405, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.23% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- qualcomm/mdm9607 firmware · qualcomm/nicobar firmware · qualcomm/qcs404 firmware · qualcomm/qcs405 firmware · qualcomm/qcs610 firmware · qualcomm/rennell firmware · qualcomm/sa6155p firmware · qualcomm/sa8155p firmware · qualcomm/saipan firmware · qualcomm/sc8180x firmware · qualcomm/sdm660 firmware · qualcomm/sdx55 firmware · qualcomm/sm6150 firmware · qualcomm/sm7150 firmware · qualcomm/sm8150 firmware · qualcomm/sm8250 firmware · qualcomm/sxr2130 firmware
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/september-2020-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/september-2020-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.