Use-after-free in Qualcomm products - CVE-2020-3671
Published: July 10, 2020 / Updated: March 3, 2021
Vulnerability identifier: #VU29649
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3671
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in Multimedia when generating a frame buffer in OpenGL ES. A remote attacker can gain elevated privileges on the target system.
Affected software
APQ8009
SXR2130
SM8250
SM8150
SDM845
Saipan
QCS405
QCM2150
Nicobar
SXR2130
SM8250
SM8150
SDM845
Saipan
QCS405
QCM2150
Nicobar
How to mitigate CVE-2020-3671
Install updates from vendor's website.