CVE-2026-21375
7.8Qualcomm · Snapdragon and Qualcomm Video Collaboration Platform
A buffer over-read vulnerability exists in specific Qualcomm chipsets and platforms during IOCTL processing due to missing size validation on output buffers.
Executive summary
A critical memory corruption vulnerability in multiple Qualcomm products allows local attackers with low privileges to potentially achieve system compromise.
Vulnerability
This vulnerability is a buffer over-read (CWE-126) triggered during IOCTL processing. It requires the attacker to have local access and low-level privileges to interact with the vulnerable driver or interface.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation could lead to unauthorized access to sensitive data, privilege escalation, or system instability, potentially resulting in significant operational downtime or the compromise of proprietary information stored within the affected hardware modules.
Remediation
Immediate Action: Review the official Qualcomm security bulletin and apply the relevant firmware or driver updates provided by your device manufacturer immediately.
Proactive Monitoring: Monitor system logs for unusual crashes or error messages related to IOCTL processing or kernel-mode driver failures.
Compensating Controls: Ensure that access to the system is strictly limited to authorized personnel to mitigate the risk posed by the local attack vector. Implement hardware-level security features and kernel protections if supported by the specific platform configuration.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for high-impact memory corruption, organizations utilizing the affected Qualcomm hardware must prioritize firmware updates. Please verify your specific hardware components against the Qualcomm security bulletin and coordinate with your device vendors to ensure patches are deployed as soon as they become available.