Description
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Published: 2026-07-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the Snapdragon camera driver that occurs when handling flash commands. Outdated LED count values are used after user‑space modification, causing memory corruption in the kernel. This flaw could allow corruption of kernel memory, potentially leading to privilege escalation or other disruptions of system integrity.

Affected Systems

Qualcomm Snapdragon platform camera drivers are affected. No specific firmware or OS version is listed in the public advisory. Any device that incorporates a Snapdragon camera subsystem—such as smartphones or tablets—might be impacted if it uses the vendor’s camera driver for flash command processing.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a local user or application capable of sending custom flash commands to the camera driver; exploitation would require sufficient privileges to interact with the driver, making it a candidate for local privilege escalation or a potential gateway to remote code execution if kernel compromise occurs.

Generated by OpenCVE AI on July 26, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Qualcomm’s July 2026 security bulletin for a driver patch and apply the firmware or software update that addresses the out‑of‑bounds write.
  • If no update is available, disable the device’s camera hardware or restrict trusted applications only using permission controls.
  • Monitor system logs for abnormal camera activity and respond promptly to any signs of exploitation.
  • Apply kernel hardening such as enabling ASLR and page‑fault protection to mitigate the impact of memory corruption.

Generated by OpenCVE AI on July 26, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Title Out-of-bounds Write in Camera Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:10:43.683Z

Reserved: 2025-12-17T04:35:45.742Z

Link: CVE-2026-21369

cve-icon Vulnrichment

Updated: 2026-07-06T20:54:41.991Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:15:04Z

Weaknesses