Description
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
Published: 2026-07-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write occurs in the Qualcomm Snapdragon camera driver when parsing JPEG commands; the driver performs unaccounted writes to its buffer during validation checks. This memory corruption can produce unexpected behavior such as application crashes or corrupted image data. The vulnerability is limited to integrity and availability problems and is not documented to enable remote code execution.

Affected Systems

All Qualcomm Snapdragon devices that include the affected camera driver are considered potentially vulnerable. No specific model or firmware version details are available, so the entire Snapdragon platform containing this driver is at risk until a vendor patch is released.

Risk and Exploitability

The CVSS score of 5.3 combined with an EPSS score of less than 1% and the absence from the CISA KEV catalog indicate that widespread exploitation is currently unlikely. The most probable attack vector is local or privileged, originating from applications that send JPEG data to the driver. If an attacker can inject crafted JPEG commands and has sufficient privileges to invoke the driver, they could induce memory corruption, but the overall risk remains moderate under current evidence.

Generated by OpenCVE AI on July 24, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Qualcomm patch that resolves the buffer overflow in JPEG parsing (CWE‑787).
  • If a patch is not yet available, restrict camera use to trusted applications or disable the camera entirely on vulnerable devices.
  • Ensure any locally implemented JPEG handling enforces strict bounds-checking before buffer writes to prevent out‑of‑bounds memory corruption.

Generated by OpenCVE AI on July 24, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
Title Out-of-bounds Write in Camera Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:10:54.219Z

Reserved: 2025-12-17T04:35:45.742Z

Link: CVE-2026-21368

cve-icon Vulnrichment

Updated: 2026-07-06T20:54:23.699Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:30:08Z

Weaknesses