Description
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Published: 2026-07-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write occurs in Qualcomm’s Snapdragon camera driver when the driver fails to validate the requested batch size or buffer plane count against defined maximums, allowing a malformed request to corrupt adjacent memory. This memory corruption can destabilize driver operation, corrupt data streams, cause crashes, or lead to unpredictable system behavior. The flaw does not provide a direct remote code execution path but can be abused to cause a denial‑of‑service or compromise application integrity.

Affected Systems

Qualcomm, Inc. Snapdragon devices equipped with the affected camera driver are impacted. The CVE does not specify particular firmware or software versions. Devices running the Snapdragon camera driver without a vendor patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of 0.0006 indicates a probability of about 0.06%, reflecting a very low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local; an attacker would need to supply crafted parameters to manipulate batch size or buffer plane counts, suggesting exploitation requires local access or compromised application privileges.

Generated by OpenCVE AI on July 31, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Qualcomm’s latest firmware or driver releases for a fix addressing the camera driver memory corruption.
  • Apply the available Qualcomm update or patch to the Snapdragon platform to eliminate the out-of-bounds write.
  • If no patch is yet available, restrict camera usage by disabling the camera driver on devices where it is not required or sandbox camera applications to prevent manipulation of batch size or buffer plane counts.

Generated by OpenCVE AI on July 31, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Title Out-of-bounds Write in Camera Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Qualcomm Fastconnect 6700 Fastconnect 6700 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware G3x Gen 2 G3x Gen 2 Firmware Iq-9075 Iq-9075 Firmware Lemans Au Lgit Lemans Au Lgit Firmware Lemansau Lemansau Firmware Netrani Netrani Firmware Pandeiro Pandeiro Firmware Qam8255p Qam8255p Firmware Qamsrv1h Qamsrv1h Firmware Qamsrv1m Qamsrv1m Firmware Qca6595 Qca6595 Firmware Qca6595au Qca6595au Firmware Qca6678aq Qca6678aq Firmware Qca6698aq Qca6698aq Firmware Qca6698au Qca6698au Firmware Qca6797aq Qca6797aq Firmware Qcm4490 Qcm4490 Firmware Qcm8838 Qcm8838 Firmware Qcs4490 Qcs4490 Firmware Qcs8550 Qcs8550 Firmware Qln1083bd Qln1083bd Firmware Qln1086bd Qln1086bd Firmware Qpa1083bd Qpa1083bd Firmware Qpa1086bd Qpa1086bd Firmware Qxm1093 Qxm1093 Firmware Qxm1094 Qxm1094 Firmware Qxm1095 Qxm1095 Firmware Qxm1096 Qxm1096 Firmware Sa7255p Sa7255p Firmware Sa7775p Sa7775p Firmware Sa8255p Sa8255p Firmware Sa8620p Sa8620p Firmware Sa8770p Sa8770p Firmware Sa9000p Sa9000p Firmware Sar2130p Sar2130p Firmware Sc8380xp Sc8380xp Firmware Sd865 5g Sd865 5g Firmware Sd 8 Gen1 5g Sd 8 Gen1 5g Firmware Sdr753 Sdr753 Firmware Sm7435 Sm7435 Firmware Sm7525 Sm7525 Firmware Sm7550 Sm7550 Firmware Sm7550p Sm7550p Firmware Sm8550p Sm8550p Firmware Snapdragon Snapdragon 460 Mobile Platform Snapdragon 460 Mobile Platform Firmware Snapdragon 4 Gen 2 Mobile Platform Snapdragon 4 Gen 2 Mobile Platform Firmware Snapdragon 662 Mobile Platform Snapdragon 662 Mobile Platform Firmware Snapdragon 6 Gen 1 Mobile Platform Snapdragon 6 Gen 1 Mobile Platform Firmware Snapdragon 6 Gen 3 Mobile Platform Snapdragon 6 Gen 3 Mobile Platform Firmware Snapdragon 7 Gen 1 Mobile Platform Snapdragon 7 Gen 1 Mobile Platform Firmware Snapdragon 8\+ Gen 2 Mobile Platform Snapdragon 8\+ Gen 2 Mobile Platform Firmware Snapdragon 8 Elite Snapdragon 8 Elite Firmware Snapdragon 8 Gen 1 Mobile Platform Snapdragon 8 Gen 1 Mobile Platform Firmware Snapdragon 8 Gen 2 Mobile Platform Snapdragon 8 Gen 2 Mobile Platform Firmware Snapdragon Ar1 Gen 1 Platform Snapdragon Ar1 Gen 1 Platform Firmware Snapdragon Xr2\+ Gen 1 Platform Snapdragon Xr2\+ Gen 1 Platform Firmware Snapdragon Xr2 5g Platform Snapdragon Xr2 5g Platform Firmware Srv1h Srv1h Firmware Srv1m Srv1m Firmware Sxr2230p Sxr2230p Firmware Sxr2330p Sxr2330p Firmware Sxr2350p Sxr2350p Firmware Wcd9370 Wcd9370 Firmware Wcd9371 Wcd9371 Firmware Wcd9375 Wcd9375 Firmware Wcd9378 Wcd9378 Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wcd9390 Wcd9390 Firmware Wcd9395 Wcd9395 Firmware Wcn3950 Wcn3950 Firmware Wcn3988 Wcn3988 Firmware Wcn6450 Wcn6450 Firmware Wcn6650 Wcn6650 Firmware Wcn6755 Wcn6755 Firmware Wcn7860 Wcn7860 Firmware Wcn7861 Wcn7861 Firmware Wcn7881 Wcn7881 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8830 Wsa8830 Firmware Wsa8832 Wsa8832 Firmware Wsa8835 Wsa8835 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware X1e80100 X1e80100 Firmware Xrv7209 Xrv7209 Firmware Xrv9209 Xrv9209 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:10:34.707Z

Reserved: 2025-12-17T04:35:45.742Z

Link: CVE-2026-21370

cve-icon Vulnrichment

Updated: 2026-07-06T20:53:18.922Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-06T21:16:53.707

Modified: 2026-07-07T16:47:47.907

Link: CVE-2026-21370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:30:04Z

Weaknesses