HIGH · 7.8

CVE-2020-11217

A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

Vulnerability Description

A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommPm3003A-
QualcommPm4125-
QualcommPm6125-
QualcommPm6150A-
QualcommPm6150L-
QualcommPm6350-
QualcommPm660-
QualcommPm660A-
QualcommPm660L-
QualcommPm7150A-
QualcommPm7150L-
QualcommPm7250-
QualcommPm7250B-
QualcommPm7350C-
QualcommPm8008-
QualcommPm8009-
QualcommPm8150A-
QualcommPm8150B-
QualcommPm8150C-
QualcommPm8150L-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11217?

CVE-2020-11217 is a vulnerability with a CVSS score of 7.8 (HIGH). A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

How severe is CVE-2020-11217?

CVE-2020-11217 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11217?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Pm3003A, Qualcomm Pm4125, Qualcomm Pm6125, Qualcomm Pm6150A, Qualcomm Pm6150L.