Vulnerability Snapshot
CVE-2020-11216 is rated CRITICAL โ exploitation is trivial or already observed in the wild and impact is severe. Patch immediately, not on the next maintenance window.
Affected technology: apq8009, apq8009w, apq8017, apq8037, apq8053, plus 5 other product variants.
Executive Summary
Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Why It Matters
CVE-2020-11216 is rated CRITICAL severity, requiring immediate attention from security teams.
CVSS Base Score: 9.8/10
Affected Technologies
Vendors: qualcomm
Products: apq8009, apq8009w, apq8017, apq8037, apq8053, apq8064au, apq8096au, aqt1000, ar8031, ar8151, csra6620, csra6640, fsm10055, fsm10056, mdm9206, mdm9650, msm8909w, msm8917, msm8920, msm8937, msm8940, msm8953, msm8996au, pm215, pm3003a, pm439, pm456, pm6125, pm6150, pm6150a, pm6150l, pm6250, pm6350, pm640a, pm640l, pm640p, pm660, pm660a, pm660l, pm670, pm670a, pm670l, pm7150a, pm7150l, pm7250, pm7250b, pm7350c, pm8004, pm8005, pm8008, pm8009, pm8150a, pm8150b, pm8150c, pm8150l, pm8250, pm8350, pm8350b, pm8350bh, pm8350bhs, pm8350c, pm855, pm855b, pm855l, pm855p, pm8909, pm8916, pm8937, pm8940, pm8953, pm8996, pm8998, pmd9607, pmd9655, pme605, pmi632, pmi8937, pmi8952, pmi8994, pmi8996, pmi8998, pmk7350, pmk8001, pmk8002, pmk8003, pmk8350, pmm6155au, pmm8155au, pmm8195au, pmm855au, pmm8996au, pmr525, pmr735a, pmr735b, pmw3100, pmx20, pmx50, pmx55, qat3514, qat3516, qat3518, qat3519, qat3522, qat3550, qat3555, qat5515, qat5516, qat5522, qat5533, qat5568, qbt1500, qbt2000, qca4020, qca6174a, qca6175a, qca6310, qca6335, qca6390, qca6391, qca6420, qca6421, qca6426, qca6430, qca6431, qca6436, qca6564, qca6564a, qca6564au, qca6574, qca6574a, qca6574au, qca6595, qca6595au, qca6696, qca9367, qca9377, qca9379, qcm4290, qcs405, qcs410, qcs4290, qcs603, qcs605, qcs610, qdm2301, qdm2302, qdm2305, qdm2307, qdm2308, qdm2310, qdm3301, qdm3302, qdm4643, qdm4650, qdm5579, qdm5620, qdm5621, qdm5650, qdm5652, qdm5670, qdm5671, qdm5677, qdm5679, qet4100, qet4101, qet4200aq, qet5100, qet5100m, qet6100, qet6110, qfe2101, qfe2520, qfe2550, qfe3340, qfe4301, qfe4302, qfe4303, qfe4305, qfe4308, qfe4309, qfe4320, qfe4373fc, qfs2530, qfs2580, qfs2608, qfs2630, qln1020, qln1021aq, qln1030, qln1031, qln1036aq, qln4640, qln4642, qln4650, qln5020, qln5030, qln5040, qpa2625, qpa4340, qpa4360, qpa4361, qpa5373, qpa5460, qpa5461, qpa5580, qpa5581, qpa6560, qpa8673, qpa8675, qpa8686, qpa8801, qpa8802, qpa8803, qpa8821, qpa8842, qpm4621, qpm4630, qpm4640, qpm4641, qpm4650, qpm5621, qpm5641, qpm5658, qpm5670, qpm5677, qpm5679, qpm5870, qpm5875, qpm6582, qpm6585, qpm6621, qpm6670, qpm8820, qpm8830, qpm8870, qpm8895, qsm7250, qsw6310, qsw8573, qsw8574, qtc410s, qtc800h, qtc800s, qtc801s, qtm525, qualcomm215, rgr7640au, rsw8577, sa6145p, sa6155, sa6155p, sa8150p, sa8155, sa8155p, sa8195p, sd205, sd210, sd429, sd439, sd450, sd455, sd460, sd632, sd636, sd660, sd662, sd665, sd675, sd6905g, sd720g, sd730, sd750g, sd765, sd765g, sd768g, sd820, sd821, sd835, sd845, sd855, sd8655g, sd8885g, sda429w, sdm429w, sdm630, sdm830, sdr051, sdr052, sdr425, sdr660, sdr660g, sdr675, sdr735, sdr735g, sdr8150, sdr8250, sdr845, sdr865, sdw2500, sdx20, sdx20m, sdx50m, sdx55, sdx55m, sdxr1, sdxr25g, sm4350, sm6250, sm6250p, sm7250p, sm7350, smb1350, smb1351, smb1354, smb1355, smb1357, smb1358, smb1360, smb1380, smb1381, smb1390, smb1394, smb1395, smb1396, smb1398, smb231, smr525, smr526, smr545, smr546, wcd9326, wcd9330, wcd9335, wcd9340, wcd9341, wcd9370, wcd9371, wcd9375, wcd9380, wcd9385, wcn3610, wcn3615, wcn3620, wcn3660b, wcn3680, wcn3680b, wcn3950, wcn3980, wcn3988, wcn3990, wcn3991, wcn3998, wcn6740, wcn6750, wcn6850, wcn6851, wcn6856, wgr7640, wsa8810, wsa8815, wsa8830, wsa8835, wtr2955, wtr2965, wtr3905, wtr3925, wtr3950, wtr4905, wtr5975
๐ก๏ธWhat Defenders Should Check
Use Vulnios to continuously monitor your exposure to CVE-2020-11216 and similar vulnerabilities.
References & Sources
How Vulnios Detects This
Vulnios scans for this vulnerability using Trivy and Grype for SBOM-based CVE matching and Vulnios CVE feed continuous monitoring against your asset inventory. Run a scan against your environment to see whether you are exposed; findings are linked back to the original CVE record so triage starts with the patch path already known.
AI Security Advisor
Powered by Gemini
Get AI-powered security recommendations tailored to this specific threat โ including risk assessment, detection guidance, MITRE ATT&CK mapping, and actionable remediation steps.
Affected Products
Sources
Related Threat Alerts
- Critical Vulnerability: CVE-2020-11136 โ qualcomm โ apq8009, apq8009w
- Critical Vulnerability: CVE-2020-11140 โ qualcomm โ apq8017, apq8037
- Critical Vulnerability: CVE-2020-3686 โ qualcomm โ apq8009, apq8009w
- Critical Vulnerability: CVE-2020-11143 โ qualcomm โ apq8009, apq8017
- Critical Vulnerability: CVE-2020-3691 โ qualcomm โ apq8009, apq8009w
- Critical Vulnerability: CVE-2020-11212 โ qualcomm โ apq8009, apq8016
Frequently Asked Questions
What is CVE-2020-11216?
CVE-2020-11216 is a critical-severity vulnerability tracked under the Common Vulnerabilities and Exposures program. Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon
Am I affected?
Check whether your environment runs apq8009, apq8009w, apq8017, apq8037, apq8053. If you operate any of those, treat yourself as in scope until you have evidence otherwise. A Vulnios scan will identify the exact assets carrying the affected version.
How urgent is the response?
Critical: do not wait for your normal patch cycle. Verify exposure today, apply the vendor patch immediately, and add detection rules for any post-exploit indicators.
How do I remediate?
Apply the vendor patch listed in the upstream advisory linked under Sources. If the patch is not yet available, follow the vendor-supplied workaround (often a config flag or feature disable) and add detections for the published exploit pattern in your SIEM. Re-scan after the patch lands to confirm the finding clears.
Where can I track exploitation activity?
Watch CISA's Known Exploited Vulnerabilities catalog for CVE-2020-11216. Cross-reference with public exploit databases and your own SIEM/IDS for indicator-of-compromise patterns. Vulnios tracks KEV status automatically and surfaces it on the asset findings view.
How does Vulnios help with this?
Vulnios continuously cross-references your asset inventory against the live CVE feed (NVD, vendor advisories, CISA KEV, and curated OSINT). When a new CVE matches your environment, you get a prioritized finding with the severity, KEV status, exploit-prediction (EPSS), and a direct path to the vendor patch. You can start a free scan from the homepage.
Protect Your Organization
Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts โ all in one platform.
Weekly threat digest
KEV-listed exploits and vendor advisories, every Monday.
One email a week. Unsubscribe any time.
Get instant alerts on Telegram
Join our public channel for real-time critical CVE alerts.
Follow @vulnios