ZeroHour

CVE-2020-11230

CVSS 3.1
6.4 medium
EPSS
<1%p3
Published
()
Modified
Description

Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

Vendors
qualcomm
Products
aqt1000 firmware, fsm10055 firmware, pm3003a firmware, pm7150a firmware, pm7150l firmware, pm7250 firmware, pm7250b firmware, pm7350c firmware, pm8004 firmware, pm8008 firmware, pm8009 firmware, pm8150a firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.