Junglewise Threat Intelligence

CVE-2026-21370: Qualcomm Snapdragon memory corruption in input validation

CVE-2026-21370 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Qualcomm, Inc. Snapdragon, Qualcomm Fastconnect 6700, Qualcomm Fastconnect 6900, Qualcomm Fastconnect 7800, Qualcomm Sc8380xp, Qualcomm Sa8255p. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in various Qualcomm Snapdragon chipsets used in mobile devices, automotive systems, and industrial IoT hardware. An attacker with local access to a device could exploit this flaw to cause system instability or potentially gain unauthorized access to sensitive data. This affects the core processing and connectivity components that manage how the device handles data batches and memory buffers.

Technical details

This vulnerability is classified as an out-of-bounds write (CWE-787) occurring during the validation of input batch sizes and buffer plane counts. When these values exceed the maximum allowed thresholds, the system fails to properly constrain memory operations, leading to memory corruption. The attack vector is local, requiring low privileges, though it has high attack complexity. Successful exploitation could allow an attacker to achieve a scope change, potentially impacting the confidentiality, integrity, and availability of the underlying system. The vulnerability affects a wide range of Snapdragon platforms including Mobile, Auto, Compute, and Industrial IOT.

Affected products

  • Qualcomm, Inc. Snapdragon FastConnect 6700, FastConnect 6900, FastConnect 7800, G3x Gen 2, IQ9 Series Platform, LeMans_AU_LGIT, LeMansAU, Netrani, Pandeiro, QAM8255P, QAMSRV1H, QAMSRV1M, QCA6595, QCA6595AU, QCA6678AQ, QCA6698AQ, QCA6698AU, QCA6797AQ, QCM4490, QCM8838, QCS4490, QCS8550, QLN1083BD, QLN1086BD, QPA1083BD, QPA1086BD, QXM1093, QXM1094, QXM1095, QXM1096, SA7255P, SA7775P, SA8255P, SA8620P, SA8770P, SA9000P, SAR2130P, SC8380XP, SD 8 Gen1 5G, SD865 5G, SDR753, SM7435

Timeline

  • 2026-07-06: advisory: Qualcomm published the July 2026 security bulletin.
  • 2026-07-06: disclosed: CVE record published to the NVD.

References

Related threats