Description
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Published: 2026-07-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability involves an out‑of‑bounds write (CWE‑787) within the Snapdragon camera driver. When a user‑space application supplies an invalid port index, the driver attempts to update prepared commands and writes beyond the bounds of the intended buffer, exceeding the supported read client limits. This memory corruption can corrupt neighboring memory and potentially interfere with camera operation or the data processed by the camera subsystem.

Affected Systems

Qualcomm Snapdragon devices that include the affected camera driver are impacted. The vendor/product list includes Qualcomm, Inc. and Snapdragon, but no specific firmware model revisions are provided. Therefore, any Snapdragon platform that incorporates the vulnerable driver and has not applied the vendor’s fix remains at risk.

Risk and Exploitability

The CVSS base score of 5.3 signals moderate severity. An EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not catalogued in CISA’s KEV. It arises from malformed input to the camera interface; the likely attack vector involves a locally or remotely running application that can control camera operations and provide out‑of‑bounds indices to trigger memory corruption.

Generated by OpenCVE AI on July 24, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor firmware or driver update that addresses the out‑of‑bounds write in the camera driver.
  • Restrict camera driver access by enforcing strict SELinux or AppArmor policies, ensuring only trusted applications can interact with it.
  • If a patch is not yet available, disable the camera subsystem or unload the driver to eliminate the exposure.

Generated by OpenCVE AI on July 24, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Title Out-of-bounds Write in Camera Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:10:27.761Z

Reserved: 2025-12-17T04:35:45.743Z

Link: CVE-2026-21384

cve-icon Vulnrichment

Updated: 2026-07-06T20:55:54.497Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:30:08Z

Weaknesses