CVE-2020-3632
u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-129
- Affected
- qualcomm/qsm8350 firmware · qualcomm/sc7180 firmware · qualcomm/sdx55 firmware · qualcomm/sdx55m firmware · qualcomm/sm6150 firmware · qualcomm/sm6250 firmware · qualcomm/sm6250p firmware · qualcomm/sm7125 firmware · qualcomm/sm7150 firmware · qualcomm/sm7150p firmware · qualcomm/sm7250 firmware · qualcomm/sm7250p firmware · qualcomm/sm8150 firmware · qualcomm/sm8150p firmware · qualcomm/sm8250 firmware · qualcomm/sm8350 firmware · qualcomm/sm8350p firmware · qualcomm/sxr2130 firmware · qualcomm/sxr2130p firmware
- Source
- product-security@qualcomm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.