Description
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption due to out-of-bounds write
Action: Immediate Patch
AI Analysis

Impact

A memory corruption flaw is introduced when Snapdragon video decoding processes decode statistics without correctly validating an offset against the structure size. The insufficient check allows a crafted offset value to write beyond the intended bounds, which can corrupt adjacent memory and, depending on the execution context, may enable arbitrary code execution or cause the system to crash. The flaw is classified under CWE-787 and is reflected in the CVSS base score of 7.8.

Affected Systems

The vulnerability affects Qualcomm Snapdragon devices; the vendor list indicates Qualcomm, Inc. as the affected manufacturer. No specific product models or firmware revisions are disclosed, and the CVE data does not provide version ranges for affected hardware or software. Administrators should verify which Snapdragon-based devices are in use and check for vendor‑released security updates or patches.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, yet the EPSS score is listed as less than 1%, suggesting a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog, further indicating limited evidence of exploitation. The likely attack vector is inferred to involve a malicious media file or stream that forces the crash or code execution during decoding, but the CVE description does not explicitly state the conditions required to trigger the flaw.

Generated by OpenCVE AI on September 17, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Qualcomm firmware or driver updates that address the out‑of‑bounds write in video decoding.
  • If no update is available, disable or limit video decoding functionality until a patch is released.
  • Enable detailed device logging, and regularly review logs for signs of memory corruption or crashes, taking corrective action if detected.

Generated by OpenCVE AI on September 17, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx5121:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx7181:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca0000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_x2_elite:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx5121_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx7181_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca0000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x2_elite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Title Out-of-bounds Write in Video
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Iqx5121 Iqx5121 Firmware Iqx7181 Iqx7181 Firmware Qca0000 Qca0000 Firmware Sc8380xp Sc8380xp Firmware Snapdragon Snapdragon X2 Elite Snapdragon X2 Elite Firmware Wcd9378c Wcd9378c Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-17T12:51:38.769Z

Reserved: 2026-01-21T12:51:13.995Z

Link: CVE-2026-24073

cve-icon Vulnrichment

Updated: 2026-09-17T12:51:27.227Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T05:16:59.760

Modified: 2026-09-22T19:33:01.183

Link: CVE-2026-24073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:45:06Z

Weaknesses