Lucene search

K
cveQualcommCVE-2020-11151
HistoryJan 21, 2021 - 10:15 a.m.

CVE-2020-11151

2021-01-2110:15:13
CWE-362
CWE-416
qualcomm
web.nvd.nist.gov
26
2
cve-2020-11151
race condition
use after free
snapdragon auto
snapdragon compute
snapdragon connectivity
snapdragon industrial iot
snapdragon mobile
snapdragon wearables
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

12.6%

Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

Affected configurations

Nvd
Node
qualcommpm3003aMatch-
OR
qualcommpm6125Match-
OR
qualcommpm6150Match-
OR
qualcommpm6150aMatch-
OR
qualcommpm6150lMatch-
OR
qualcommpm6350Match-
OR
qualcommpm640aMatch-
OR
qualcommpm640lMatch-
OR
qualcommpm640pMatch-
OR
qualcommpm7150aMatch-
OR
qualcommpm7150lMatch-
OR
qualcommpm7250Match-
OR
qualcommpm7250bMatch-
OR
qualcommpm8008Match-
OR
qualcommpm8009Match-
OR
qualcommpm8150aMatch-
OR
qualcommpm8150bMatch-
OR
qualcommpm8150cMatch-
OR
qualcommpm8150lMatch-
OR
qualcommpm8250Match-
OR
qualcommpmi632Match-
OR
qualcommpmk8002Match-
OR
qualcommpmk8003Match-
OR
qualcommpmm8195auMatch-
OR
qualcommpmm855auMatch-
OR
qualcommpmr525Match-
OR
qualcommpmr735aMatch-
OR
qualcommpmr735bMatch-
OR
qualcommpmx55Match-
OR
qualcommqat3516Match-
OR
qualcommqat3518Match-
OR
qualcommqat3519Match-
OR
qualcommqat3522Match-
OR
qualcommqat3550Match-
OR
qualcommqat3555Match-
OR
qualcommqat5515Match-
OR
qualcommqat5516Match-
OR
qualcommqat5522Match-
OR
qualcommqat5533Match-
OR
qualcommqbt1500Match-
OR
qualcommqbt2000Match-
OR
qualcommqca6390Match-
OR
qualcommqca6391Match-
OR
qualcommqca6421Match-
OR
qualcommqca6426Match-
OR
qualcommqca6431Match-
OR
qualcommqca6436Match-
OR
qualcommqca6574aMatch-
OR
qualcommqca6574auMatch-
OR
qualcommqca6584auMatch-
OR
qualcommqca6595Match-
OR
qualcommqca6595auMatch-
OR
qualcommqca6696Match-
OR
qualcommqcm4290Match-
OR
qualcommqcs4290Match-
OR
qualcommqdm2301Match-
OR
qualcommqdm2305Match-
OR
qualcommqdm2307Match-
OR
qualcommqdm2308Match-
OR
qualcommqdm2310Match-
OR
qualcommqdm3301Match-
OR
qualcommqdm5620Match-
OR
qualcommqdm5621Match-
OR
qualcommqdm5650Match-
OR
qualcommqdm5652Match-
OR
qualcommqdm5670Match-
OR
qualcommqdm5671Match-
OR
qualcommqdm5677Match-
OR
qualcommqdm5679Match-
OR
qualcommqet4101Match-
OR
qualcommqet5100Match-
OR
qualcommqet6100Match-
OR
qualcommqet6110Match-
OR
qualcommqfs2530Match-
OR
qualcommqfs2580Match-
OR
qualcommqln4642Match-
OR
qualcommqln4650Match-
OR
qualcommqln5020Match-
OR
qualcommqln5030Match-
OR
qualcommqln5040Match-
OR
qualcommqpa2625Match-
OR
qualcommqpa4360Match-
OR
qualcommqpa5580Match-
OR
qualcommqpa5581Match-
OR
qualcommqpa6560Match-
OR
qualcommqpa8673Match-
OR
qualcommqpa8686Match-
OR
qualcommqpa8801Match-
OR
qualcommqpa8802Match-
OR
qualcommqpa8803Match-
OR
qualcommqpa8821Match-
OR
qualcommqpa8842Match-
OR
qualcommqpm4650Match-
OR
qualcommqpm5621Match-
OR
qualcommqpm5658Match-
OR
qualcommqpm5670Match-
OR
qualcommqpm5677Match-
OR
qualcommqpm5679Match-
OR
qualcommqpm6582Match-
OR
qualcommqpm6585Match-
OR
qualcommqpm8820Match-
OR
qualcommqpm8830Match-
OR
qualcommqpm8870Match-
OR
qualcommqpm8895Match-
OR
qualcommqsm7250Match-
OR
qualcommqsw8574Match-
OR
qualcommqtc410sMatch-
OR
qualcommqtc800hMatch-
OR
qualcommqtc801sMatch-
OR
qualcommqtm525Match-
OR
qualcommsa6155pMatch-
OR
qualcommsa8150pMatch-
OR
qualcommsa8155Match-
OR
qualcommsa8195pMatch-
OR
qualcommsd460Match-
OR
qualcommsd662Match-
OR
qualcommsd665Match-
OR
qualcommsd675Match-
OR
qualcommsd6905gMatch-
OR
qualcommsd750gMatch-
OR
qualcommsd765Match-
OR
qualcommsd765gMatch-
OR
qualcommsd768gMatch-
OR
qualcommsd8655gMatch-
OR
qualcommsda429wMatch-
OR
qualcommsdr425Match-
OR
qualcommsdr660Match-
OR
qualcommsdr660gMatch-
OR
qualcommsdr735Match-
OR
qualcommsdr8250Match-
OR
qualcommsdr865Match-
OR
qualcommsdx55Match-
OR
qualcommsdx55mMatch-
OR
qualcommsdxr25gMatch-
OR
qualcommsm7250pMatch-
OR
qualcommsmb1354Match-
OR
qualcommsmb1355Match-
OR
qualcommsmb1390Match-
OR
qualcommsmb1395Match-
OR
qualcommsmb1396Match-
OR
qualcommsmr525Match-
OR
qualcommsmr526Match-
OR
qualcommwcd9341Match-
OR
qualcommwcd9370Match-
OR
qualcommwcd9375Match-
OR
qualcommwcd9380Match-
OR
qualcommwcd9385Match-
OR
qualcommwcn3610Match-
OR
qualcommwcn3620Match-
OR
qualcommwcn3660bMatch-
OR
qualcommwcn3950Match-
OR
qualcommwcn3980Match-
OR
qualcommwcn3988Match-
OR
qualcommwcn3991Match-
OR
qualcommwcn3998Match-
OR
qualcommwcn6750Match-
OR
qualcommwcn6850Match-
OR
qualcommwcn6851Match-
OR
qualcommwgr7640Match-
OR
qualcommwsa8810Match-
OR
qualcommwsa8815Match-
OR
qualcommwsa8830Match-
OR
qualcommwsa8835Match-
OR
qualcommwtr2965Match-
OR
qualcommwtr3925Match-
VendorProductVersionCPE
qualcommpm3003a-cpe:2.3:h:qualcomm:pm3003a:-:*:*:*:*:*:*:*
qualcommpm6125-cpe:2.3:h:qualcomm:pm6125:-:*:*:*:*:*:*:*
qualcommpm6150-cpe:2.3:h:qualcomm:pm6150:-:*:*:*:*:*:*:*
qualcommpm6150a-cpe:2.3:h:qualcomm:pm6150a:-:*:*:*:*:*:*:*
qualcommpm6150l-cpe:2.3:h:qualcomm:pm6150l:-:*:*:*:*:*:*:*
qualcommpm6350-cpe:2.3:h:qualcomm:pm6350:-:*:*:*:*:*:*:*
qualcommpm640a-cpe:2.3:h:qualcomm:pm640a:-:*:*:*:*:*:*:*
qualcommpm640l-cpe:2.3:h:qualcomm:pm640l:-:*:*:*:*:*:*:*
qualcommpm640p-cpe:2.3:h:qualcomm:pm640p:-:*:*:*:*:*:*:*
qualcommpm7150a-cpe:2.3:h:qualcomm:pm7150a:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 1651

CNA Affected

[
  {
    "product": "Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "PM3003A, PM6125, PM6150, PM6150A, PM6150L, PM6350, PM640A, PM640L, PM640P, PM7150A, PM7150L, PM7250, PM7250B, PM8008, PM8009, PM8150A, PM8150B, PM8150C, PM8150L, PM8250, PMI632, PMK8002, PMK8003, PMM8195AU, PMM855AU, PMR525, PMR735A, PMR735B, PMX55, QAT3516, QAT3518, QAT3519, QAT3522, QAT3550, QAT3555, QAT5515, QAT5516, QAT5522, QAT5533, QBT1500, QBT2000, QCA6390, QCA6391, QCA6421, QCA6426, QCA6431, QCA6436, QCA6574A, QCA6574AU, QCA6584AU, QCA6595, QCA6595AU, QCA6696, QCM4290, QCS4290, QDM2301, QDM2305, QDM2307, QDM2308, QDM2310, QDM3301, QDM5620, QDM5621, QDM5650, QDM5652, QDM5670, QDM5671, QDM5677, QDM5679, QET4101, QET5100, QET6100, QET6110, QFS2530, QFS2580, QLN4642, QLN4650, QLN5020, QLN5030, QLN5040, QPA2625, QPA4360, QPA5580, QPA5581, QPA6560, QPA8673, QPA8686, QPA8801, QPA8802, QPA8803, QPA8821, QPA8842, QPM4650, QPM5621, QPM5658, QPM5670, QPM5677, QPM5679, QPM6582, QPM6585, QPM8820, QPM8830, QPM8870, QPM8895, QSM7250, QSW8574, QTC410S, QTC800H, QTC801S, QTM525, SA6155P, SA8150P, SA815 ...[truncated*]"
      }
    ]
  }
]

Social References

More

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-11151