CVE-2026-21378 is a memory corruption vulnerability in camera sensor drivers that occurs when an output buffer is accessed during IOCTL processing without proper size validation. This flaw affects an undetermined range of devices utilizing the vulnerable camera sensor driver code. The vulnerability carries a HIGH severity rating (CVSS 7.8) with a local attack vector requiring low privilege access but no user interaction, resulting in potential compromise of confidentiality, integrity, and availability. Exploitation requires local access to the affected system, though the attack requires minimal complexity to execute. Currently, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no indication of active exploitation in the wild. The relatively low EPSS score of 0.00013 suggests minimal real-world exploitation activity at present, though the moderate FAUCET Risk Score of 48.0 warrants attention from organizations running affected hardware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wcn3950_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.