Description
Memory Corruption when processing fastboot commands to set display mode.
Published: 2026-06-01
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from faulty validation of syntactic correctness of input received while processing fastboot commands to set the display mode, resulting in a memory corruption flaw. The flaw is categorized as CWE‑1286 and could allow an attacker to corrupt memory during the fastboot command handling process. If successfully exploited, this could lead to a crash, denial of service, or potentially arbitrary code execution, depending on the attacker’s objectives and system state.

Affected Systems

The flaw affects Qualcomm, Inc. Snapdragon devices. No specific product versions are listed in the available data, so all Snapdragon models that support fastboot display mode configuration may be impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation at this time. Based on the fact that the flaw is triggered by fastboot commands, the likely attack vector is local or physical access via a USB connector where the device is in fastboot mode. Consequently, the risk is moderate to high for environments where fastboot mode is accessible or when devices are exposed to untrusted connections.

Generated by OpenCVE AI on June 1, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm Snapdragon firmware update that contains the memory corruption fix.
  • Disable physical access to fastboot mode by disabling USB debugging and enforcing secure boot or limiting the USB ports used for device access.
  • Implement strict physical security controls and port locking to prevent unauthorized use of fastboot commands.

Generated by OpenCVE AI on June 1, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing fastboot commands to set display mode.
Title Improper Validation of Syntactic Correctness of Input in Display
Weaknesses CWE-1286
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-06-01T22:05:41.591Z

Reserved: 2026-01-21T12:51:13.996Z

Link: CVE-2026-24092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-01T23:16:20.033

Modified: 2026-06-01T23:16:20.033

Link: CVE-2026-24092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T01:00:11Z

Weaknesses