Description
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
Published: 2026-06-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cryptographic oversight in the parsing of partition table entries introduces a flaw that allows an attacker to modify the boot flow without proper authentication. The weakness, identified as Missing Authentication for a Critical Function, means that anyone able to influence the partition data can redirect or alter the sequence of modules loaded during system startup, potentially leading to unauthorized code execution or denial of service. The impact is confined to the boot process itself, but because the boot loader often establishes initial security state, tampering can have lasting system‐wide effects.

Affected Systems

The vulnerability affects Qualcomm, Inc.’s Snapdragon line of mobile processors. Any device that implements the Snapdragon firmware containing the flawed partition table handling is considered susceptible.

Risk and Exploitability

The CVSS score of 7.1 marks this vulnerability as high severity. No EPSS data is available, suggesting that public exploitation evidence is limited and the likelihood may be moderate. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to embed malicious configuration data in the partition table, requiring either firmware modification or physical access to the device’s storage. The path to exploitation is contingent upon the ability to write to the partition table and bypass existing code signing checks, a condition not trivially available to remote attackers.

Generated by OpenCVE AI on June 1, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest Qualcomm Snapdragon firmware update that corrects the cryptographic validation of partition table entries.
  • Restrict write access to the device’s partition and configuration storage, ensuring only privileged users or trusted boot components can modify it.
  • Enable or reinforce secure boot and trust chain mechanisms to verify the integrity of bootloader and configuration data.
  • Implement monitoring on the boot configuration to detect unauthorized changes and alert administrators promptly.

Generated by OpenCVE AI on June 1, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
Title Missing Authentication for Critical Function in HLOS
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-06-01T22:05:39.371Z

Reserved: 2026-01-21T12:51:13.996Z

Link: CVE-2026-24090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-01T23:16:19.793

Modified: 2026-06-01T23:16:19.793

Link: CVE-2026-24090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T00:15:40Z

Weaknesses