Description
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Published: 2026-07-06
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer over‑read (CWE‑126) that occurs when memory is allocated with sizes exceeding the maximum allowed value. This can result in memory corruption that affects program data integrity.

Affected Systems

Qualcomm Snapdragon chipsets; any device that incorporates a Snapdragon processor could be impacted unless a vendor patch has been applied, as detailed in Qualcomm’s July 2026 security bulletin. Specific affected firmware versions are not disclosed.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. No specific attack vector is disclosed, so the threat assessment relies on the CVSS metrics alone.

Generated by OpenCVE AI on July 29, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the firmware update for Qualcomm Snapdragon processors as distributed in the July 2026 security bulletin.
  • If a patch is not yet available, add bounds checking to any custom code that requests memory allocations, ensuring allocation sizes do not exceed the allowed maximum and mitigating the buffer over‑read (CWE‑126).
  • Continuously monitor device logs for crashes or abnormal memory usage that may arise from a buffer over‑read (CWE‑126), and replace the vulnerable component with the patched version as soon as possible.

Generated by OpenCVE AI on July 29, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Title Buffer Over-read in Windows Compute
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T03:56:18.731Z

Reserved: 2025-12-17T04:35:45.743Z

Link: CVE-2026-21379

cve-icon Vulnrichment

Updated: 2026-07-06T20:55:07.755Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T16:15:03Z

Weaknesses