CVE-2020-3658 - Qualcomm Msm8909w Firmware, Qualcomm Apq8009 Firmware and Qualcomm Msm8905 Firmware

Critical 9.1

Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Affected software

Qualcomm Msm8909w Firmware

Qualcomm Apq8009 Firmware

Qualcomm Msm8905 Firmware

Qualcomm Kamorta Firmware

Qualcomm Mdm9607 Firmware

Qualcomm Sm8250 Firmware

Qualcomm Sm8150 Firmware

Qualcomm Rennell Firmware

Qualcomm Sm7150 Firmware

Qualcomm Qm215 Firmware

Qualcomm Msm8940 Firmware

Qualcomm Sdm429 Firmware

Qualcomm Qca6574au Firmware

Qualcomm Msm8996 Firmware

Qualcomm Sdm429w Firmware

Qualcomm Sxr2130 Firmware

Qualcomm Sdm660 Firmware

Qualcomm Apq8096au Firmware

Qualcomm Msm8953 Firmware

Qualcomm Sdm630 Firmware

Qualcomm Apq8053 Firmware

Qualcomm Mdm9207c Firmware

Qualcomm Apq8098 Firmware

Qualcomm Msm8996au Firmware

Qualcomm Saipan Firmware

Qualcomm Sdm845 Firmware

Qualcomm Sxr1130 Firmware

Qualcomm Qcs605 Firmware

Qualcomm Msm8920 Firmware

Qualcomm Sda660 Firmware

Qualcomm Sdm636 Firmware

Qualcomm Sdx20 Firmware

Qualcomm Mdm9206 Firmware

Qualcomm Apq8017 Firmware

Qualcomm Msm8998 Firmware

Qualcomm Sdm710 Firmware

Qualcomm Sm6150 Firmware

Qualcomm Sdm670 Firmware

Qualcomm Sdm450 Firmware

Qualcomm Msm8937 Firmware

Qualcomm Qcs405 Firmware

Qualcomm Sdm439 Firmware

Qualcomm Msm8917 Firmware

Qualcomm Sdm632 Firmware

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.