CVE-2020-3642
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL after free/destroy of the object in Snapdragon Consumer IOT, Snapdragon Mobile in Kamorta, QCS605, Rennell, Saipan, SDM670, SDM710,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL after free/destroy of the object in Snapdragon Consumer IOT, Snapdragon Mobile in Kamorta, QCS605, Rennell, Saipan, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- qualcomm/kamorta firmware · qualcomm/qcs605 firmware · qualcomm/rennell firmware · qualcomm/saipan firmware · qualcomm/sdm670 firmware · qualcomm/sdm710 firmware · qualcomm/sdm845 firmware · qualcomm/sm6150 firmware · qualcomm/sm7150 firmware · qualcomm/sm8150 firmware · qualcomm/sm8250 firmware · qualcomm/sxr1130 firmware · qualcomm/sxr2130 firmware
- Source
- product-security@qualcomm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.