CVE-2020-3625

HIGH

Snapdragon Auto/Snapdragon Consumer IOT/Snapdragon Mobile - Buffer ...

Title source: llm
STIX 2.1

Description

When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in SM8250, SXR2130

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 9.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (2)
qualcomm/sm8250_firmware
qualcomm/sxr2130_firmware
Published Jun 02, 2020
Tracked Since Feb 18, 2026