CVE-2020-11151

Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

Published: 2021-01-21 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2020-11151 is rated Low Risk (26.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2020-11151

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.04% 0.13% +0.09%
2 2023-03-07 0.89% 0.04% -0.84%
3 2022-04-01 0.89%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2020-11151

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.4 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.5 5.9 [email protected]
6.9 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.4 10.0 [email protected]

Weakness enumeration for CVE-2020-11151

Affected software / configurations for CVE-2020-11151

Vendor Product Version Raw CPE
qualcomm pm3003a cpe:2.3:h:qualcomm:pm3003a:-:*:*:*:*:*:*:*
qualcomm pm6125 cpe:2.3:h:qualcomm:pm6125:-:*:*:*:*:*:*:*
qualcomm pm6150 cpe:2.3:h:qualcomm:pm6150:-:*:*:*:*:*:*:*
qualcomm pm6150a cpe:2.3:h:qualcomm:pm6150a:-:*:*:*:*:*:*:*
qualcomm pm6150l cpe:2.3:h:qualcomm:pm6150l:-:*:*:*:*:*:*:*
qualcomm pm6350 cpe:2.3:h:qualcomm:pm6350:-:*:*:*:*:*:*:*
qualcomm pm640a cpe:2.3:h:qualcomm:pm640a:-:*:*:*:*:*:*:*
qualcomm pm640l cpe:2.3:h:qualcomm:pm640l:-:*:*:*:*:*:*:*
qualcomm pm640p cpe:2.3:h:qualcomm:pm640p:-:*:*:*:*:*:*:*
qualcomm pm7150a cpe:2.3:h:qualcomm:pm7150a:-:*:*:*:*:*:*:*
qualcomm pm7150l cpe:2.3:h:qualcomm:pm7150l:-:*:*:*:*:*:*:*
qualcomm pm7250 cpe:2.3:h:qualcomm:pm7250:-:*:*:*:*:*:*:*
qualcomm pm7250b cpe:2.3:h:qualcomm:pm7250b:-:*:*:*:*:*:*:*
qualcomm pm8008 cpe:2.3:h:qualcomm:pm8008:-:*:*:*:*:*:*:*
qualcomm pm8009 cpe:2.3:h:qualcomm:pm8009:-:*:*:*:*:*:*:*
qualcomm pm8150a cpe:2.3:h:qualcomm:pm8150a:-:*:*:*:*:*:*:*
qualcomm pm8150b cpe:2.3:h:qualcomm:pm8150b:-:*:*:*:*:*:*:*
qualcomm pm8150c cpe:2.3:h:qualcomm:pm8150c:-:*:*:*:*:*:*:*
qualcomm pm8150l cpe:2.3:h:qualcomm:pm8150l:-:*:*:*:*:*:*:*
qualcomm pm8250 cpe:2.3:h:qualcomm:pm8250:-:*:*:*:*:*:*:*
qualcomm pmi632 cpe:2.3:h:qualcomm:pmi632:-:*:*:*:*:*:*:*
qualcomm pmk8002 cpe:2.3:h:qualcomm:pmk8002:-:*:*:*:*:*:*:*
qualcomm pmk8003 cpe:2.3:h:qualcomm:pmk8003:-:*:*:*:*:*:*:*
qualcomm pmm8195au cpe:2.3:h:qualcomm:pmm8195au:-:*:*:*:*:*:*:*
qualcomm pmm855au cpe:2.3:h:qualcomm:pmm855au:-:*:*:*:*:*:*:*
qualcomm pmr525 cpe:2.3:h:qualcomm:pmr525:-:*:*:*:*:*:*:*
qualcomm pmr735a cpe:2.3:h:qualcomm:pmr735a:-:*:*:*:*:*:*:*
qualcomm pmr735b cpe:2.3:h:qualcomm:pmr735b:-:*:*:*:*:*:*:*
qualcomm pmx55 cpe:2.3:h:qualcomm:pmx55:-:*:*:*:*:*:*:*
qualcomm qat3516 cpe:2.3:h:qualcomm:qat3516:-:*:*:*:*:*:*:*
qualcomm qat3518 cpe:2.3:h:qualcomm:qat3518:-:*:*:*:*:*:*:*
qualcomm qat3519 cpe:2.3:h:qualcomm:qat3519:-:*:*:*:*:*:*:*
qualcomm qat3522 cpe:2.3:h:qualcomm:qat3522:-:*:*:*:*:*:*:*
qualcomm qat3550 cpe:2.3:h:qualcomm:qat3550:-:*:*:*:*:*:*:*
qualcomm qat3555 cpe:2.3:h:qualcomm:qat3555:-:*:*:*:*:*:*:*
qualcomm qat5515 cpe:2.3:h:qualcomm:qat5515:-:*:*:*:*:*:*:*
qualcomm qat5516 cpe:2.3:h:qualcomm:qat5516:-:*:*:*:*:*:*:*
qualcomm qat5522 cpe:2.3:h:qualcomm:qat5522:-:*:*:*:*:*:*:*
qualcomm qat5533 cpe:2.3:h:qualcomm:qat5533:-:*:*:*:*:*:*:*
qualcomm qbt1500 cpe:2.3:h:qualcomm:qbt1500:-:*:*:*:*:*:*:*
qualcomm qbt2000 cpe:2.3:h:qualcomm:qbt2000:-:*:*:*:*:*:*:*
qualcomm qca6390 cpe:2.3:h:qualcomm:qca6390:-:*:*:*:*:*:*:*
qualcomm qca6391 cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*
qualcomm qca6421 cpe:2.3:h:qualcomm:qca6421:-:*:*:*:*:*:*:*
qualcomm qca6426 cpe:2.3:h:qualcomm:qca6426:-:*:*:*:*:*:*:*
qualcomm qca6431 cpe:2.3:h:qualcomm:qca6431:-:*:*:*:*:*:*:*
qualcomm qca6436 cpe:2.3:h:qualcomm:qca6436:-:*:*:*:*:*:*:*
qualcomm qca6574a cpe:2.3:h:qualcomm:qca6574a:-:*:*:*:*:*:*:*
qualcomm qca6574au cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*
qualcomm qca6584au cpe:2.3:h:qualcomm:qca6584au:-:*:*:*:*:*:*:*
qualcomm qca6595 cpe:2.3:h:qualcomm:qca6595:-:*:*:*:*:*:*:*
qualcomm qca6595au cpe:2.3:h:qualcomm:qca6595au:-:*:*:*:*:*:*:*
qualcomm qca6696 cpe:2.3:h:qualcomm:qca6696:-:*:*:*:*:*:*:*
qualcomm qcm4290 cpe:2.3:h:qualcomm:qcm4290:-:*:*:*:*:*:*:*
qualcomm qcs4290 cpe:2.3:h:qualcomm:qcs4290:-:*:*:*:*:*:*:*
qualcomm qdm2301 cpe:2.3:h:qualcomm:qdm2301:-:*:*:*:*:*:*:*
qualcomm qdm2305 cpe:2.3:h:qualcomm:qdm2305:-:*:*:*:*:*:*:*
qualcomm qdm2307 cpe:2.3:h:qualcomm:qdm2307:-:*:*:*:*:*:*:*
qualcomm qdm2308 cpe:2.3:h:qualcomm:qdm2308:-:*:*:*:*:*:*:*
qualcomm qdm2310 cpe:2.3:h:qualcomm:qdm2310:-:*:*:*:*:*:*:*
qualcomm qdm3301 cpe:2.3:h:qualcomm:qdm3301:-:*:*:*:*:*:*:*
qualcomm qdm5620 cpe:2.3:h:qualcomm:qdm5620:-:*:*:*:*:*:*:*
qualcomm qdm5621 cpe:2.3:h:qualcomm:qdm5621:-:*:*:*:*:*:*:*
qualcomm qdm5650 cpe:2.3:h:qualcomm:qdm5650:-:*:*:*:*:*:*:*
qualcomm qdm5652 cpe:2.3:h:qualcomm:qdm5652:-:*:*:*:*:*:*:*
qualcomm qdm5670 cpe:2.3:h:qualcomm:qdm5670:-:*:*:*:*:*:*:*
qualcomm qdm5671 cpe:2.3:h:qualcomm:qdm5671:-:*:*:*:*:*:*:*
qualcomm qdm5677 cpe:2.3:h:qualcomm:qdm5677:-:*:*:*:*:*:*:*
qualcomm qdm5679 cpe:2.3:h:qualcomm:qdm5679:-:*:*:*:*:*:*:*
qualcomm qet4101 cpe:2.3:h:qualcomm:qet4101:-:*:*:*:*:*:*:*
qualcomm qet5100 cpe:2.3:h:qualcomm:qet5100:-:*:*:*:*:*:*:*
qualcomm qet6100 cpe:2.3:h:qualcomm:qet6100:-:*:*:*:*:*:*:*
qualcomm qet6110 cpe:2.3:h:qualcomm:qet6110:-:*:*:*:*:*:*:*
qualcomm qfs2530 cpe:2.3:h:qualcomm:qfs2530:-:*:*:*:*:*:*:*
qualcomm qfs2580 cpe:2.3:h:qualcomm:qfs2580:-:*:*:*:*:*:*:*
qualcomm qln4642 cpe:2.3:h:qualcomm:qln4642:-:*:*:*:*:*:*:*
qualcomm qln4650 cpe:2.3:h:qualcomm:qln4650:-:*:*:*:*:*:*:*
qualcomm qln5020 cpe:2.3:h:qualcomm:qln5020:-:*:*:*:*:*:*:*
qualcomm qln5030 cpe:2.3:h:qualcomm:qln5030:-:*:*:*:*:*:*:*
qualcomm qln5040 cpe:2.3:h:qualcomm:qln5040:-:*:*:*:*:*:*:*

References for CVE-2020-11151

cvelogic Threat Intelligence