CVE-2021-35126

HIGH

Qualcomm Firmware - Memory Corruption in DSP Service via Improper Input Validation

Title source: llm
STIX 2.1

Description

Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-129
Status published
Products (26)
qualcomm/qam8295p_firmware
qualcomm/qca6391_firmware
qualcomm/qca6696_firmware
qualcomm/qcm6490_firmware
qualcomm/qcs6490_firmware
qualcomm/sa8295p_firmware
qualcomm/sd778g_firmware
qualcomm/sd780g_firmware
qualcomm/sd888_5g_firmware
qualcomm/sd888_firmware
... and 16 more
Published Jun 14, 2022
Tracked Since Feb 18, 2026