Impact
The vulnerability is an out‑of‑bounds write in the Snapdragon camera driver that occurs when handling flash commands. Outdated LED count values are used after user‑space modification, causing memory corruption in the kernel. This flaw could allow corruption of kernel memory, potentially leading to privilege escalation or other disruptions of system integrity.
Affected Systems
Qualcomm Snapdragon platform camera drivers are affected. No specific firmware or OS version is listed in the public advisory. Any device that incorporates a Snapdragon camera subsystem—such as smartphones or tablets—might be impacted if it uses the vendor’s camera driver for flash command processing.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a local user or application capable of sending custom flash commands to the camera driver; exploitation would require sufficient privileges to interact with the driver, making it a candidate for local privilege escalation or a potential gateway to remote code execution if kernel compromise occurs.
OpenCVE Enrichment