← Vulnerability feed

Vulnerability record · CVE-2026-21385 · published 2 March 2026

CVE-2026-21385: Qualcomm chipset firmware memory corruption via alignment integer overflow

Qualcomm · Sm7675p Firmware

A memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It affects a broad set of Snapdragon mobile, smart audio and smart display platforms, and CISA added it to the Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

7.8 CVSS 3.1 High CISA KEV since 3 Mar 2026 EPSS 1.2% · top 32.0% CWE-190 · Integer overflow
7.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
150Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Memory corruption while using alignments for memory allocation.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a high-severity local memory corruption issue with confirmed inclusion in CISA KEV, though EPSS is low and no ransomware use is documented.

What it is

A memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It affects a broad set of Snapdragon mobile, smart audio and smart display platforms, and CISA added it to the Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

Impact

An attacker who can run code locally on the device can corrupt memory and potentially gain code execution or escalate privileges in the affected firmware context, with high impact to confidentiality, integrity and availability.

Attack surface

The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by a local actor already able to execute code on the device rather than remotely over a network.

Exploitation

CISA added this CVE to the KEV catalog on 2026-03-03 with a remediation due date of 2026-03-24, indicating known exploitation; EPSS is low at roughly 1.3 percent for the next 30 days, and no ransomware campaign use is documented.

What to do

  • Apply the Qualcomm March 2026 security bulletin firmware updates for all listed chipsets as the first action.
  • Apply the corresponding Android March 2026 security bulletin updates on affected devices.
  • If vendor mitigations are unavailable, follow CISA BOD 22-01 guidance or discontinue use of the affected product per the KEV required action.
  • Track the 2026-03-24 KEV due date and verify remediation across all affected Snapdragon, smart audio and smart display platforms.
  • Limit local code execution and untrusted app installation on affected devices to reduce exposure to the local attack vector.

Detection

  • Monitor for anomalous crashes or memory corruption indicators in firmware and kernel logs on affected Qualcomm-based devices.
  • Audit devices for the presence of the March 2026 Qualcomm and Android security patch levels.
  • Hunt for unexpected local privilege escalation or code execution activity originating from low-privileged local processes on affected platforms.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-21385 to the Known Exploited Vulnerabilities catalog on 3 March 2026 as "Qualcomm Multiple Chipsets Memory Corruption Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 March 2026.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21385 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-33107Qualcomm Graphics Linux integer overflow memory corruptionCVE-2023-33107 is an integer overflow (CWE-190) in Qualcomm Graphics Linux that causes memory corruption when a shared virtual memory region is assig…KEVEPSS 0.89%analysed7.8CVE-2023-33106Qualcomm GPU AUX Command Sync Point Memory CorruptionCVE-2023-33106 is a memory corruption flaw in Qualcomm chipsets triggered when a large list of sync points is submitted in an AUX command to the IOCT…KEVEPSS 0.92%analysed7.8CVE-2023-33063Qualcomm DSP Services use-after-free memory corruptionCVE-2023-33063 is a use-after-free memory corruption flaw in Qualcomm DSP Services, triggered during a remote call from the high-level operating syst…KEVEPSS 0.69%analysed7.8CVE-2022-22071Qualcomm chipset shell memory use-after-free via IOCTL munmapA use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while pro…KEVEPSS 0.46%analysed7.8CVE-2020-11261Qualcomm Snapdragon chipsets memory corruption via improper allocation size checkQualcomm Snapdragon firmware fails to return an error when a user application requests a very large memory allocation, leading to memory corruption (…KEVEPSS 1.6%analysed7.8CVE-2021-1905Qualcomm Snapdragon chipsets use-after-free in memory mapping handlingA use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes oper…KEVEPSS 1.5%analysed7.5CVE-2025-27038Qualcomm Adreno GPU driver use-after-free in Chrome graphics renderingA use-after-free (CWE-416) in Qualcomm Adreno GPU drivers causes memory corruption while rendering graphics in Chrome. It affects a broad set of Qual…KEVEPSS 1.0%analysed5.5CVE-2021-1906Qualcomm Snapdragon GPU address deregistration failure causes allocation denialImproper handling of address deregistration on failure in Qualcomm Snapdragon chipsets can cause subsequent GPU address allocation to fail. The flaw …KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2026-21385), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.