Vulnerability Description
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wcd9375 Firmware | - |
| Qualcomm | Wcd9375 | - |
| Qualcomm | Wcd9378C Firmware | - |
| Qualcomm | Wcd9378C | - |
| Qualcomm | Wcd9380 Firmware | - |
| Qualcomm | Wcd9380 | - |
| Qualcomm | Wcd9385 Firmware | - |
| Qualcomm | Wcd9385 | - |
| Qualcomm | Wcn3950 Firmware | - |
| Qualcomm | Wcn3950 | - |
| Qualcomm | Wcn3988 Firmware | - |
| Qualcomm | Wcn3988 | - |
| Qualcomm | Wsa8810 Firmware | - |
| Qualcomm | Wsa8810 | - |
| Qualcomm | Wsa8815 Firmware | - |
| Qualcomm | Wsa8815 | - |
| Qualcomm | Wsa8830 Firmware | - |
| Qualcomm | Wsa8830 | - |
| Qualcomm | Wsa8832 Firmware | - |
| Qualcomm | Wsa8832 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-21378?
CVE-2026-21378 is a vulnerability with a CVSS score of 7.8 (HIGH). Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
How severe is CVE-2026-21378?
CVE-2026-21378 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-21378?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Wcd9375 Firmware, Qualcomm Wcd9375, Qualcomm Wcd9378C Firmware, Qualcomm Wcd9378C, Qualcomm Wcd9380 Firmware.