ZeroHour

CVE-2026-24075

large

Race-condition memory corruption in Qualcomm device control driver (CVE-2026-24075)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

A Qualcomm device control handler contains a memory-corruption flaw (buffer over-read, CWE-126) caused by improper synchronization when multiple threads issue concurrent IOCTL requests to the driver. A local, low-privileged attacker could trigger the race condition by sending simultaneous IOCTL requests, corrupting memory in the driver. Because the CVSS vector grants high confidentiality, integrity, and availability impact from a local attack with low privileges, successful exploitation likely yields local privilege escalation to kernel-level compromise of the host. Any system running the affected Qualcomm driver component is exposed; the specific product names and version ranges are not enumerated in the available data. Exploitation status: no public proof-of-concept is known and the flaw is not listed in CISA KEV.

What to do: Check Qualcomm's security bulletin for CVE-2026-24075 and apply the updated driver package provided by Qualcomm or your device OEM (e.g., via Windows Update or the OEM support portal) as soon as a fixed version is published. Until patched, restrict untrusted local code execution on systems running the affected driver, since exploitation requires a low-privileged local attacker. Verify installed driver versions against the bulletin once Qualcomm confirms affected and fixed ranges.

Affected
Qualcomm
Estimated exposure
largelikely hundreds of thousands to millions of devices (Qualcomm driver components ship broadly with Snapdragon-based PCs and Android-connectivity software), but… — Qualcomm drivers and chipset software are preinstalled on or installed for very large populations of Windows PCs with Qualcomm modems and Snapdragon laptops, and Android device drivers are widely downloaded; because the bulletin data does…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

Weakness
CWE-126
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.