CVE-2026-21383: Reusing a Nonce, Key Pair in Encryption in HLOS
Published Jul 6, 2026
·Updated
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
Affected Software
106 affected components
All of the following
Qualcomm Fastconnect 6900 Firmware
Qualcomm Fastconnect 6900
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Lemans Au Lgit Firmware
Qualcomm Lemans Au Lgit
All of the following
Qualcomm Lemansau Firmware
Qualcomm Lemansau
All of the following
Qualcomm Pandeiro Firmware
Qualcomm Pandeiro
All of the following
Qualcomm Qam8255p Firmware
Qualcomm Qam8255p
All of the following
Qualcomm Qam8397p Firmware
Qualcomm Qam8397p
All of the following
Qualcomm Qam8797p Firmware
Qualcomm Qam8797p
All of the following
Qualcomm Qamsrv1h Firmware
Qualcomm Qamsrv1h
All of the following
Qualcomm Qamsrv1m Firmware
Qualcomm Qamsrv1m
All of the following
Qualcomm Qca6595au Firmware
Qualcomm Qca6595au
All of the following
Qualcomm Qca6696 Firmware
Qualcomm Qca6696
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Qca6797aq Firmware
Qualcomm Qca6797aq
All of the following
Qualcomm Qca8695au Firmware
Qualcomm Qca8695au
All of the following
Qualcomm Qdu1000 Firmware
Qualcomm Qdu1000
All of the following
Qualcomm Qdu1110 Firmware
Qualcomm Qdu1110
All of the following
Qualcomm Qdu1210 Firmware
Qualcomm Qdu1210
All of the following
Qualcomm Qdx1010 Firmware
Qualcomm Qdx1010
All of the following
Qualcomm Qdx1011 Firmware
Qualcomm Qdx1011
All of the following
Qualcomm Qln1083bd Firmware
Qualcomm Qln1083bd
All of the following
Qualcomm Qln1086bd Firmware
Qualcomm Qln1086bd
All of the following
Qualcomm Qpa1083bd Firmware
Qualcomm Qpa1083bd
All of the following
Qualcomm Qpa1086bd Firmware
Qualcomm Qpa1086bd
All of the following
Qualcomm Qualcomm Dragonwing X100 Accelerator Card Firmware
Qualcomm Qualcomm Dragonwing X100 Accelerator Card
All of the following
Qualcomm Qxm1093 Firmware
Qualcomm Qxm1093
All of the following
Qualcomm Qxm1094 Firmware
Qualcomm Qxm1094
All of the following
Qualcomm Qxm1095 Firmware
Qualcomm Qxm1095
All of the following
Qualcomm Qxm1096 Firmware
Qualcomm Qxm1096
All of the following
Qualcomm Sa7255p Firmware
Qualcomm Sa7255p
All of the following
Qualcomm Sa7775p Firmware
Qualcomm Sa7775p
All of the following
Qualcomm Sa8255p Firmware
Qualcomm Sa8255p
All of the following
Qualcomm Sa8620p Firmware
Qualcomm Sa8620p
All of the following
Qualcomm Sa8770p Firmware
Qualcomm Sa8770p
All of the following
Qualcomm Sa9000p Firmware
Qualcomm Sa9000p
All of the following
Qualcomm Sar1165p Firmware
Qualcomm Sar1165p
All of the following
Qualcomm Sar2130p Firmware
Qualcomm Sar2130p
All of the following
Qualcomm Snapdragon Ar1 Gen 1 Platform Firmware
Qualcomm Snapdragon Ar1 Gen 1 Platform
All of the following
Qualcomm Snapdragon Ar1\+ Gen 1 Platform Firmware
Qualcomm Snapdragon Ar1\+ Gen 1 Platform
All of the following
Qualcomm Srv1h Firmware
Qualcomm Srv1h
All of the following
Qualcomm Srv1m Firmware
Qualcomm Srv1m
All of the following
Qualcomm Sxr2230p Firmware
Qualcomm Sxr2230p
All of the following
Qualcomm Sxr2250p Firmware
Qualcomm Sxr2250p
All of the following
Qualcomm Wcd9380 Firmware
Qualcomm Wcd9380
All of the following
Qualcomm Wcd9385 Firmware
Qualcomm Wcd9385
All of the following
Qualcomm Wcn3950 Firmware
Qualcomm Wcn3950
All of the following
Qualcomm Wcn7860 Firmware
Qualcomm Wcn7860
All of the following
Qualcomm Wcn7861 Firmware
Qualcomm Wcn7861
All of the following
Qualcomm Wsa8830 Firmware
Qualcomm Wsa8830
All of the following
Qualcomm Wsa8832 Firmware
Qualcomm Wsa8832
All of the following
Qualcomm Wsa8835 Firmware
Qualcomm Wsa8835
All of the following
Qualcomm Xrv7209 Firmware
Qualcomm Xrv7209
All of the following
Qualcomm Xrv9209 Firmware
Qualcomm Xrv9209
Event History
Jul 6, 2026
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21383?
The severity of CVE-2026-21383 is classified as high with a score of 7.1.
2
What type of vulnerability is CVE-2026-21383?
CVE-2026-21383 is a cryptographic issue related to reusing a nonce and key pair in AES-GCM encryption.
3
What are the potential impacts of CVE-2026-21383?
CVE-2026-21383 can lead to severe confidentiality and integrity issues due to the reuse of initialization vectors in encryption.
4
How can I mitigate CVE-2026-21383?
To mitigate CVE-2026-21383, ensure that a unique nonce is generated for each encryption operation.
5
Is CVE-2026-21383 applicable to all systems using AES-GCM?
CVE-2026-21383 specifically affects systems that do not utilize a unique initialization vector for AES-GCM key wrapping.