CVE-2026-21385: Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Memory corruption while using alignments for memory allocation.
Other sources
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services for affected Qualcomm chipsets.
- Operational
Discontinue use of the product if mitigations are unavailable for the affected Qualcomm chipsets.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21385?
CVE-2026-21385 is classified as a high severity vulnerability due to the potential for memory corruption.
How do I fix CVE-2026-21385?
To mitigate CVE-2026-21385, ensure that your Qualcomm chipset is updated with the latest security patches.
What type of vulnerability is CVE-2026-21385?
CVE-2026-21385 is an integer overflow or wraparound vulnerability that leads to memory corruption.
Which devices are affected by CVE-2026-21385?
CVE-2026-21385 affects multiple Qualcomm chipsets that utilize alignments for memory allocation.
What are the potential impacts of CVE-2026-21385?
Exploitation of CVE-2026-21385 could allow an attacker to execute arbitrary code or cause a denial of service.