EXPOSURES › CVE-2020-11261
CVE-2020-11261
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm Snapdragon chipsets suffered from a memory corruption vulnerability due to improper input validation on large memory allocation requests.
This improper input validation flaw allowed memory corruption when user applications requested huge memory allocations, a vulnerability that was actively exploited in the wild. DIB organizations must ensure their IoT and embedded systems running Qualcomm hardware are patched, as this could lead to system compromise or data exfiltration. The failure highlights the risk of relying on unpatched hardware in critical infrastructure.
Shame score — The vulnerability was actively exploited in the wild and linked to memory corruption, indicating a significant security lapse in Qualcomm's chipsets.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables