Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Release Date: 03rd of March 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-21385 is a high-severity vulnerability (CVSS 7.8) affecting the graphics subsystem of certain Android devices that use Qualcomm chipsets. The flaw exists in the Qualcomm Adreno GPU graphics driver, which is responsible for handling graphics processing and memory allocation.

The vulnerability results from an integer overflow (CWE-190) during memory allocation calculations. When the system incorrectly calculates the required memory buffer size, it can lead to memory corruption, allowing data to overflow into restricted memory areas.

 

References