Buffer over-read in Qualcomm products - CVE-2020-11132

 

Buffer over-read in Qualcomm products - CVE-2020-11132

Published: July 7, 2025


Vulnerability identifier: #VU112429
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L  /SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11132
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged application to read and manipulate data.

The vulnerability exists due to improper input validation in Boot. A local privileged application can read and manipulate data.


Affected software

SDM845
SDX55
SDX24
SDM710
SDM670
SDA845
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
QCS405
MSM8998
MSM8905
MDM9650
MDM9607
MDM9206
MDM9150
APQ8098
APQ8096AU
SC8180X
SA6155P
APQ8009
QCS605
SM6115P
SM6115
SM4250P
SM4250
SM4125
SDX55M
SDX50M
SDM850
SM6125
SDM830
SDM712
SDM640
SDM1000
SDA855
SDA670
SM7250
WCD9330
SXR2130P
SXR1120
SM8150P
SM7250P
SDA640
SM7225
SM7150P
SM7125
SM6350
SM6250P
SM6250
SM6150P
MDM9628
QCM4290
MSM8909
MSM8608
MSM8209
MSM8208
MSM8108
QCS410
MDM9250
MDM9207
MDM9205
MDM8207
SA6155
SC8180XP
SC8180X+SDX55
SC7180
SA8195P
SA8155P
SA8155
SA8150P
SA6150P
SA6145P
SA515M
SA415M
QSM8250
QCS610
QCS603
QCS4290

How to mitigate CVE-2020-11132

Install security update from vendor's website.


External References

Related Security Bulletins