Junglewise Threat Intelligence

CVE-2026-21366: Qualcomm component memory corruption in packet processing

CVE-2026-21366 · Severity: high · CVSS 7.8 · Published 2026-08-04

Technologies: Qualcomm Qca6595au, Qualcomm Qca6696 Firmware, Qualcomm Qca6696, Qualcomm Qam8295p Firmware, Qualcomm Qam8295p, Qualcomm Sa8295p, Qualcomm Sa8255p, Qualcomm Sa8295p Firmware. Vendors: Qualcomm.

Executive brief

A Qualcomm component processes network packets and fails to properly validate packet size when values approach the maximum allowed limit, leading to memory corruption. An attacker with network access could exploit this to crash the affected system or potentially execute arbitrary code, disrupting services or compromising device integrity.

Technical details

This vulnerability is a memory corruption flaw in packet processing logic within a Qualcomm component. The root cause is insufficient validation of packet sizes when they reach near-maximum values, allowing an attacker to trigger out-of-bounds memory access. The attack vector is network-based and does not require authentication or user interaction. Successful exploitation can lead to denial of service or arbitrary code execution depending on memory layout and attacker capabilities. A patch is expected to be available from Qualcomm through their security bulletins.

Affected products

  • Qualcomm <UNKNOWN> <UNKNOWN>

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: advisory: Qualcomm security bulletin published

References

Related threats