PT-2021-9271 · Qualcomm · Qualcomm Snapdragon
Published
2021-06-09
·
Updated
2021-06-16
·
CVE-2020-11262
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon (affected versions not specified)
Description
A race condition between command submission and context destruction can lead to an invalid context being added to a list, resulting in a use-after-free issue. This issue affects various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qualcomm Snapdragon