Impact
An out-of-bounds write occurs in Qualcomm’s Snapdragon camera driver when the driver fails to validate the requested batch size or buffer plane count against defined maximums, allowing a malformed request to corrupt adjacent memory. This memory corruption can destabilize driver operation, corrupt data streams, cause crashes, or lead to unpredictable system behavior. The flaw does not provide a direct remote code execution path but can be abused to cause a denial‑of‑service or compromise application integrity.
Affected Systems
Qualcomm, Inc. Snapdragon devices equipped with the affected camera driver are impacted. The CVE does not specify particular firmware or software versions. Devices running the Snapdragon camera driver without a vendor patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score, shown as less than 1%, reflects a low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local; an attacker would need to supply crafted parameters to manipulate batch size or buffer plane counts, suggesting exploitation requires local access or compromised application privileges.
OpenCVE Enrichment