← Vulnerability feed

Vulnerability record · CVE-2020-11282 · published 22 February 2021

CVE-2020-11282: Qualcomm apq8009 vulnerability

Qualcomm · Apq8009

Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

7.8 CVSS 3.1 High EPSS 0.18% · top 93.0%
7.8CVSS 3.1 base score, v2 4.6
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11282 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-11283Qualcomm apq8009 out-of-bounds write vulnerabilityA buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,…EPSS 0.71%9.8CVE-2020-3691Qualcomm apq8009 vulnerabilityPossible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snap…EPSS 1.1%9.8CVE-2020-3686Qualcomm apq8009 classic buffer overflow vulnerabilityPossible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of arr…EPSS 1.2%9.8CVE-2020-11197Qualcomm apq8009 integer overflow vulnerabilityPossible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with inval…EPSS 0.91%9.8CVE-2020-11216Qualcomm apq8009 out-of-bounds read vulnerabilityBuffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdrago…EPSS 0.91%9.8CVE-2020-11212Qualcomm apq8009 out-of-bounds read vulnerabilityOut of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapd…EPSS 0.87%9.8CVE-2020-11213Qualcomm apq8009 out-of-bounds read vulnerabilityOut of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon C…EPSS 0.87%9.8CVE-2020-11167Qualcomm apq8009w integer overflow vulnerabilityMemory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2020-11282), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.