ZeroHour

CVE-2020-11148

CVSS 3.1
6.7 medium
EPSS
<1%p11
Published
()
Modified
Description

Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggered and callback instance is deleted in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

Vendors
qualcomm
Products
apq8017, apq8053, msm8917, msm8953, pm215, pm3003a, pm439, pm6125, pm6150, pm6150a, pm6150l, pm6350
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.