Junglewise Threat Intelligence

CVE-2026-24083: Qualcomm device driver memory corruption in IOCTL handling

CVE-2026-24083 · Severity: high · CVSS 7.8 · Published 2026-08-04

Technologies: Qualcomm Qca6696 Firmware, Qualcomm Qca6696, Qualcomm Qam8295p Firmware, Qualcomm Qam8295p, Qualcomm Sa8295p, Qualcomm Sa8295p Firmware. Vendors: Qualcomm.

Executive brief

A Qualcomm device driver fails to properly validate arguments passed through IOCTL (input/output control) requests, allowing an attacker with local access to trigger memory corruption. This could lead to system instability, denial of service, or potentially arbitrary code execution on affected devices.

Technical details

This vulnerability is a memory corruption flaw in a Qualcomm device driver's IOCTL request handler. The driver does not properly validate arguments supplied by callers, allowing malformed or invalid parameters to be processed unsafely. The vulnerability requires local access to trigger (either via direct device access or a local unprivileged process). Successful exploitation can cause heap or stack corruption, leading to crash, information disclosure, or code execution depending on memory layout and exploitation technique. Patches are available from Qualcomm's August 2026 security bulletin.

Affected products

  • Qualcomm <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats