CVE-2020-11261 — Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
2021-12-01 • CISA Known Exploited Vulnerability
[event] Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Qualcomm |
| Product | Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
| CWE | CWE-20 |
| CVE ID | CVE-2020-11261 |
| Date Added | 2021-12-01 |
| Due Date | 2022-06-01 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-06-01