CVE-2026-21381
7.6Qualcomm · Snapdragon
A buffer over-read in Qualcomm Snapdragon platforms allows for a denial of service when processing oversized service data frames within the neighborhood awareness network protocol.
Executive summary
A buffer over-read vulnerability in various Qualcomm Snapdragon platforms could allow a privileged attacker to trigger a denial of service condition.
Vulnerability
This vulnerability is caused by a buffer over-read (CWE-126) that occurs when the device processes a service data frame with an excessive length. Based on the CVSS vector (PR:H), this attack requires high privileges to execute.
Business impact
The exploitation of this vulnerability results in a denial of service, which can lead to significant operational disruption for devices relying on these Snapdragon components. With a CVSS score of 7.6, the risk is classified as High, reflecting the potential for critical system instability if the affected hardware becomes unresponsive during essential operations.
Remediation
Immediate Action: Review the April 2026 Qualcomm security bulletin for specific firmware updates and apply them to all affected Snapdragon platforms as soon as they become available.
Proactive Monitoring: Monitor device logs for unexpected reboots or crashes that correlate with neighborhood awareness network activity.
Compensating Controls: Restrict access to the network environment where these devices operate to ensure that only authorized and trusted entities can interact with the affected protocol services.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity rating, administrators must prioritize the identification of all vulnerable Snapdragon hardware within their infrastructure. Once the vendor releases the necessary firmware patches, they should be deployed immediately to prevent potential service disruption caused by this buffer over-read flaw.