CVE-2026-21376 is a memory corruption vulnerability in camera sensor drivers that occurs when output buffers are accessed during IOCTL processing without proper size validation. The flaw allows attackers to trigger buffer overflows that could compromise system integrity and confidentiality. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring low complexity and user-level privileges, but no user interaction. Successful exploitation grants attackers the ability to achieve confidentiality, integrity, and availability impacts on affected systems. Based on current indicators, CVE-2026-21376 has not been added to CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00006 indicates minimal likelihood of near-term exploitation despite the moderate FAUCET Risk Score of 49.0, suggesting this remains an emerging threat requiring proactive patching rather than urgent emergency remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6800_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.