CVE-2026-21380

7.8

Qualcomm · Snapdragon

A use after free vulnerability in Qualcomm Snapdragon platforms allows for memory corruption via deprecated DMABUF IOCTL calls.

Executive summary

A high severity memory corruption vulnerability in various Qualcomm Snapdragon components, stemming from improper use of DMABUF IOCTL calls, poses a significant risk of system compromise.

Vulnerability

This is a use after free vulnerability (CWE-416) triggered by the use of deprecated DMABUF IOCTL calls to manage video memory. Successful exploitation requires local access with low privileges to interact with the vulnerable IOCTL interface.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high potential for impact on confidentiality, integrity, and availability. Because the flaw allows for memory corruption, a local attacker could potentially escalate privileges, cause system instability, or execute arbitrary code within the context of the affected hardware driver.

Remediation

Immediate Action: Review the April 2026 Qualcomm security bulletin for specific firmware or driver patches applicable to your device and apply them as soon as they are made available by your hardware manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or kernel panics that may indicate memory corruption attempts targeting video drivers.

Compensating Controls: Ensure that device access is strictly managed to prevent unauthorized local users or potentially malicious applications from executing low-level IOCTL calls.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of memory corruption vulnerabilities, this issue should be prioritized for remediation once the vendor releases specific firmware updates. Organizations utilizing the affected Qualcomm Snapdragon platforms should coordinate with their device vendors to ensure that security patches are deployed across their hardware fleet to mitigate the risk of local privilege escalation.

More Qualcomm CVEs

Sources