CVE-2020-11147

MEDIUM

Qualcomm PMx Firmware - Use-After-Free in Audio Module Object Handling

Title source: llm
STIX 2.1

Description

Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (50)
qualcomm/aqt1000_firmware
qualcomm/pm3003a_firmware
qualcomm/pm456_firmware
qualcomm/pm6125_firmware
qualcomm/pm6150_firmware
qualcomm/pm6150a_firmware
qualcomm/pm6150l_firmware
qualcomm/pm6250_firmware
qualcomm/pm6350_firmware
qualcomm/pm660_firmware
... and 40 more
Published Feb 22, 2021
Tracked Since Feb 18, 2026