CVE-2026-21371 is a memory corruption vulnerability arising from insufficient size validation when retrieving output buffers, affecting systems that process improperly validated buffer operations. This flaw has a CVSS score of 7.8 (HIGH) with a local attack vector requiring low privileges and no user interaction, making it a moderate-to-high severity concern. The vulnerability enables attackers with local access to achieve high-impact outcomes including confidentiality loss, integrity compromise, and availability disruption. Currently, there is no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on threat tracking lists. The EPSS score of 0.000060 suggests this vulnerability ranks lower than typical CVEs in terms of exploitation probability, though the FAUCET risk score of 49.0 indicates it warrants monitoring and patching within standard vulnerability management cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:snapdragon_8cx_compute_platform_\"poipu_pro\"_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:snapdragon_8cx_gen_2_5g_compute_platform_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:snapdragon_8cx_gen_2_5g_compute_platform_\"poipu_pro\"_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:snapdragon_8cx_gen_3_compute_platform_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.