Description
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Published: 2026-08-04
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory corruption occurs when the fingerprint trusted application processes malformed request parameters. The vulnerability can lead to overwritten memory and possible arbitrary code execution or denial of services. This weakness is a classic buffer overflow, classified as CWE‑120.

Affected Systems

The affected product is Qualcomm’s Snapdragon platform, specifically the fingerprint trusted application component. No specific firmware or build versions are listed, so any Snapdragon device that includes the unpatched fingerprint TA is potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. EPSS data is not available, making exploitation probability unclear, and the vulnerability is not listed in the CISA KEV catalogue. Attack vectors are not explicitly stated in the advisory; however, the likely attack path involves an attacker supplying crafted data to the fingerprint TA, which may be local or rely on elevated privileges. Given the lack of mitigation details, the risk remains elevated pending a patch.

Generated by OpenCVE AI on August 4, 2026 at 19:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Snapdragon firmware or operating system to the latest version that includes the vendor‑supplied fix for the fingerprint trusted application.
  • If an immediate update is unavailable, restrict access to the fingerprint TA and enforce strict input validation or sandboxing to limit the impact of malformed requests.
  • Enable any available memory protection mechanisms (e.g., stack canaries, address space layout randomization) to reduce the likelihood that an overflow will lead to code execution.

Generated by OpenCVE AI on August 4, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Memory Corruption when handling malformed request parameters in the fingerprint TA.
Title Buffer Copy Without Checking Size of Input in Biometrics
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 6700 Fastconnect 6700 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Qam8255p Qam8255p Firmware Qam8295p Qam8295p Firmware Qca6574au Qca6574au Firmware Qca6595au Qca6595au Firmware Qca6678aq Qca6678aq Firmware Qca6696 Qca6696 Firmware Sa6145p Sa6145p Firmware Sa6150p Sa6150p Firmware Sa6155p Sa6155p Firmware Sa8145p Sa8145p Firmware Sa8150p Sa8150p Firmware Sa8155p Sa8155p Firmware Sa8195p Sa8195p Firmware Sa8255p Sa8255p Firmware Sa8295p Sa8295p Firmware Sa8540p Sa8540p Firmware Sa9000p Sa9000p Firmware Snapdragon Sw6100 Sw6100 Firmware Sw6100p Sw6100p Firmware Themisto Themisto Firmware Wcd9378c Wcd9378c Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware X2000077 X2000077 Firmware X2000086 X2000086 Firmware X2000090 X2000090 Firmware X2000092 X2000092 Firmware X2000094 X2000094 Firmware Xg101002 Xg101002 Firmware Xg101032 Xg101032 Firmware Xg101039 Xg101039 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-08-05T03:56:28.839Z

Reserved: 2026-01-21T12:51:13.995Z

Link: CVE-2026-24080

cve-icon Vulnrichment

Updated: 2026-08-04T15:59:53.582Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T16:16:23.770

Modified: 2026-08-06T18:32:54.930

Link: CVE-2026-24080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')