← Vulnerability feed

Vulnerability record · CVE-2020-11277 · published 22 February 2021

CVE-2020-11277: Qualcomm pm3003a firmware race condition vulnerability

Qualcomm · Pm3003a Firmware

Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

7.4 CVSS 3.1 High EPSS 0.12% · top 98.4% CWE-362 · Race conditionCWE-416 · Use after free
7.4CVSS 3.1 base score, v2 6.9
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-11261Qualcomm Snapdragon chipsets memory corruption via improper allocation size checkQualcomm Snapdragon firmware fails to return an error when a user application requests a very large memory allocation, leading to memory corruption (…KEVEPSS 1.6%analysed7.8CVE-2021-1905Qualcomm Snapdragon chipsets use-after-free in memory mapping handlingA use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes oper…KEVEPSS 1.5%analysed5.5CVE-2021-1906Qualcomm Snapdragon GPU address deregistration failure causes allocation denialImproper handling of address deregistration on failure in Qualcomm Snapdragon chipsets can cause subsequent GPU address allocation to fail. The flaw …KEVEPSS 0.52%analysed9.8CVE-2020-11134Qualcomm aqt1000 firmware out-of-bounds write vulnerabilityPossible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute i…EPSS 0.80%9.8CVE-2020-11182Qualcomm aqt1000 firmware out-of-bounds write vulnerabilityPossible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Sna…EPSS 0.81%9.8CVE-2021-1910Qualcomm apq8009 firmware double free vulnerabilityDouble free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO…EPSS 0.58%9.8CVE-2020-11279Qualcomm apq8009 firmware integer overflow vulnerabilityMemory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute,…EPSS 0.82%9.8CVE-2020-11227Qualcomm apq8009 firmware out-of-bounds write vulnerabilityOut of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon…EPSS 0.91%

Source: NIST National Vulnerability Database (record CVE-2020-11277), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.