CVE-2026-24075
largeRace-condition memory corruption in Qualcomm device control driver (CVE-2026-24075)
A Qualcomm device control handler contains a memory-corruption flaw (buffer over-read, CWE-126) caused by improper synchronization when multiple threads issue concurrent IOCTL requests to the driver. A local, low-privileged attacker could trigger the race condition by sending simultaneous IOCTL requests, corrupting memory in the driver. Because the CVSS vector grants high confidentiality, integrity, and availability impact from a local attack with low privileges, successful exploitation likely yields local privilege escalation to kernel-level compromise of the host. Any system running the affected Qualcomm driver component is exposed; the specific product names and version ranges are not enumerated in the available data. Exploitation status: no public proof-of-concept is known and the flaw is not listed in CISA KEV.
What to do: Check Qualcomm's security bulletin for CVE-2026-24075 and apply the updated driver package provided by Qualcomm or your device OEM (e.g., via Windows Update or the OEM support portal) as soon as a fixed version is published. Until patched, restrict untrusted local code execution on systems running the affected driver, since exploitation requires a low-privileged local attacker. Verify installed driver versions against the bulletin once Qualcomm confirms affected and fixed ranges.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.