CVE-2026-21384
published 2026-07-06CVE-2026-21384: Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
PriorityP428medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.06%
0.0th percentile
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
| qualcomm_inc | snapdragon | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Qualcomm Snapdragon memory corruption (EUVD-2026-41931)
vuldb·2026-07-06·CVSS 5.3
CVE-2026-21384 [MEDIUM] Qualcomm Snapdragon memory corruption (EUVD-2026-41931)
A vulnerability classified as very critical was found in Qualcomm Snapdragon. This affects an unknown function. Executing a manipulation can lead to memory corruption.
This vulnerability is handled as CVE-2026-21384. It is possible to launch the attack on the local host. There is not any exploit available.
GHSA
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
ghsa_unreviewed·2026-07-06
CVE-2026-21384 [MEDIUM] CWE-787 Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-06
Published