CVE-2026-21381

7.6

Qualcomm · Snapdragon

A buffer over-read in Qualcomm Snapdragon platforms allows for a denial of service when processing oversized service data frames within the neighborhood awareness network protocol.

Executive summary

A buffer over-read vulnerability in various Qualcomm Snapdragon platforms could allow a privileged attacker to trigger a denial of service condition.

Vulnerability

This vulnerability is caused by a buffer over-read (CWE-126) that occurs when the device processes a service data frame with an excessive length. Based on the CVSS vector (PR:H), this attack requires high privileges to execute.

Business impact

The exploitation of this vulnerability results in a denial of service, which can lead to significant operational disruption for devices relying on these Snapdragon components. With a CVSS score of 7.6, the risk is classified as High, reflecting the potential for critical system instability if the affected hardware becomes unresponsive during essential operations.

Remediation

Immediate Action: Review the April 2026 Qualcomm security bulletin for specific firmware updates and apply them to all affected Snapdragon platforms as soon as they become available.

Proactive Monitoring: Monitor device logs for unexpected reboots or crashes that correlate with neighborhood awareness network activity.

Compensating Controls: Restrict access to the network environment where these devices operate to ensure that only authorized and trusted entities can interact with the affected protocol services.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity rating, administrators must prioritize the identification of all vulnerable Snapdragon hardware within their infrastructure. Once the vendor releases the necessary firmware patches, they should be deployed immediately to prevent potential service disruption caused by this buffer over-read flaw.

More Qualcomm CVEs

Sources