Buffer overflow in Qualcomm products - CVE-2020-11210

 

Buffer overflow in Qualcomm products - CVE-2020-11210

Published: April 5, 2021


Vulnerability identifier: #VU51886
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11210
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in RPM region due to improper XPU configuration. A malicious application can trigger memory corruption and execute arbitrary code with elevated privileges.


Affected software

SDR425
SMB1396
SMB1355
SMB1354
SMB1351
SM4125
SDR735G
SDR735
SDR660
SMR526
SD662
SD480
SD460
QTM525
QTC410S
QSW8574
WCN3991
WTR3925
WTR2965
WSA8815
WSA8810
WGR7640
WCN6850
WCN3999
WCN3998
QSW8573
WCN3988
WCN3980
WCN3950
WCN3910
WCD9385
WCD9375
WCD9370
PM8008
QAT5516
QAT5515
QAT3555
QAT3522
QAT3519
PMK8003
PMI632
PMD9655
QCA6390
PM7250B
PM6350
PM6150L
PM6150A
PM6125
PM4250
PM4125
AR8035
QCA9984
QCM2290
QCM4290
QCS2290
QCS4290
QDM2301
QDM2302
QET4101
QET6105
QPA4360
QPA4361
QPA6560
QPA8673
QSW6310
SD665
QCS405
Google Android

How to mitigate CVE-2020-11210

Install updates from vendor's website.

Google Android - addressed in versions 9.0 2021-04-05, 10 2021-04-05, 11 2021-04-05

External References

Related Security Bulletins