CVE-2026-21378
Published Apr 6, 2026Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
32 CVEs tagged to qualcomm / wsa8815 — 0 Critical, 25 High, 7 Medium, 0 Low, 0 Unrated.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
Memory corruption while processing a frame request from user.
Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU commands.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Memory corruption when kernel driver attempts to trigger hardware fences.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Memory corruption during session sign renewal request calls in HLOS.
Memory corruption when keymaster operation imports a shared key.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.