Description
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Published: 2026-07-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write occurs in Qualcomm’s Snapdragon camera driver when the driver fails to validate the requested batch size or buffer plane count against defined maximums, allowing a malformed request to corrupt adjacent memory. This memory corruption can destabilize driver operation, corrupt data streams, cause crashes, or lead to unpredictable system behavior. The flaw does not provide a direct remote code execution path but can be abused to cause a denial‑of‑service or compromise application integrity.

Affected Systems

Qualcomm, Inc. Snapdragon devices equipped with the affected camera driver are impacted. The CVE does not specify particular firmware or software versions. Devices running the Snapdragon camera driver without a vendor patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score, shown as less than 1%, reflects a low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local; an attacker would need to supply crafted parameters to manipulate batch size or buffer plane counts, suggesting exploitation requires local access or compromised application privileges.

Generated by OpenCVE AI on July 26, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Qualcomm’s latest firmware or driver releases for a fix addressing the camera driver memory corruption.
  • Apply the available Qualcomm update or patch to the Snapdragon platform to eliminate the out-of-bounds write.
  • If no patch is yet available, restrict camera usage by disabling the camera driver on devices where it is not required or sandbox camera applications to prevent manipulation of batch size or buffer plane counts.

Generated by OpenCVE AI on July 26, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Title Out-of-bounds Write in Camera Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:10:34.707Z

Reserved: 2025-12-17T04:35:45.742Z

Link: CVE-2026-21370

cve-icon Vulnrichment

Updated: 2026-07-06T20:53:18.922Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:15:04Z

Weaknesses