PT-2021-9281 · Qualcomm · Snapdragon Mobile+3
Published
2021-05-07
·
Updated
2022-07-12
·
CVE-2020-11273
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Snapdragon Auto (affected versions not specified)
Snapdragon Compute (affected versions not specified)
Snapdragon Connectivity (affected versions not specified)
Snapdragon Mobile (affected versions not specified)
Description
The issue arises from the teardown of the histogram type KPI, which assumes the existence of histogram binning information. However, when this information is missing, it leads to a null pointer access due to a lack of null check. This affects various Snapdragon products.
Recommendations
For Snapdragon Auto, apply configuration changes to handle missing histogram binning information.
For Snapdragon Compute, restrict access to the histogram type KPI when binning information is not available.
For Snapdragon Connectivity, consider implementing null checks to prevent null pointer access.
For Snapdragon Mobile, as a temporary workaround, consider disabling the histogram type KPI until a proper fix is available.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Mobile