CVE-2026-21369
Published Jul 6, 2026Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
24 CVEs tagged to qualcomm / wcn3950 — 1 Critical, 19 High, 4 Medium, 0 Low, 0 Unrated.
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Cryptographic issue may occur while encrypting license data.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption during the FRS UDS generation process.
Memory corruption while processing IPA statistics, when there are no active clients registered.
Memory corruption while processing GPU page table switch.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while processing user packets to generate page faults.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Memory corruption when keymaster operation imports a shared key.
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Transient DOS during music playback of ALAC content.
Information disclosure while handling beacon or probe response frame in STA.
Transient DOS while decoding message of size that exceeds the available system memory.
Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it.
Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOT
RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile