CVE-2018-13920

EUVD-2018-5854
Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820A, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX24
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8909w_firmware
-
qualcommqcs605_firmware
-
qualcommqm215_firmware
-
qualcommsd_425_firmware
-
qualcommsd_439_firmware
-
qualcommsd_429_firmware
-
qualcommsd_450_firmware
-
qualcommsd_625_firmware
-
qualcommsd_632_firmware
-
qualcommsd_636_firmware
-
qualcommsd_712_firmware
-
qualcommsd_710_firmware
-
qualcommsd_670_firmware
-
qualcommsd_820a_firmware
-
qualcommsd_845_firmware
-
qualcommsd_850_firmware
-
qualcommsd_855_firmware
-
qualcommsdm439_firmware
-
qualcommsdm630_firmware
-
qualcommsdm660_firmware
-
qualcommsdx24_firmware
-
𝑥
= Vulnerable software versions