Executive brief
A Qualcomm device driver fails to properly validate arguments passed through IOCTL (input/output control) requests, allowing an attacker with local access to trigger memory corruption. This could lead to system instability, denial of service, or potentially arbitrary code execution on affected devices.
Technical details
This vulnerability is a memory corruption flaw in a Qualcomm device driver's IOCTL request handler. The driver does not properly validate arguments supplied by callers, allowing malformed or invalid parameters to be processed unsafely. The vulnerability requires local access to trigger (either via direct device access or a local unprivileged process). Successful exploitation can cause heap or stack corruption, leading to crash, information disclosure, or code execution depending on memory layout and exploitation technique. Patches are available from Qualcomm's August 2026 security bulletin.
Affected products
- Qualcomm <UNKNOWN>
Timeline
- 2026-08-04: disclosed