Impact
This vulnerability involves an out‑of‑bounds write (CWE‑787) within the Snapdragon camera driver. When a user‑space application supplies an invalid port index, the driver attempts to update prepared commands and writes beyond the bounds of the intended buffer, exceeding the supported read client limits. This memory corruption can corrupt neighboring memory and potentially interfere with camera operation or the data processed by the camera subsystem.
Affected Systems
Qualcomm Snapdragon devices that include the affected camera driver are impacted. The vendor/product list includes Qualcomm, Inc. and Snapdragon, but no specific firmware model revisions are provided. Therefore, any Snapdragon platform that incorporates the vulnerable driver and has not applied the vendor’s fix remains at risk.
Risk and Exploitability
The CVSS base score of 5.3 signals moderate severity. An EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not catalogued in CISA’s KEV. It arises from malformed input to the camera interface; the likely attack vector involves a locally or remotely running application that can control camera operations and provide out‑of‑bounds indices to trigger memory corruption.
OpenCVE Enrichment