7.6
CVE-2026-21381 - Buffer Over-read in WLAN Firmware
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
7.8
CVE-2026-21380 - Use After Free in DSP Service
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
7.8
CVE-2026-21378 - Buffer Over-read in Camera
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
7.8
CVE-2026-21376 - Buffer Over-read in Camera
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
7.8
CVE-2026-21375 - Buffer Over-read in Camera
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
7.8
CVE-2026-21374 - Buffer Over-read in Camera
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
7.8
CVE-2026-21373 - Buffer Over-read in Camera
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
7.8
CVE-2026-21372 - Heap-Based Buffer Overflow in Power Management IC
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
7.8
CVE-2026-21371 - Buffer Over-read in WinBlast Driver
Memory Corruption when retrieving output buffer with insufficient size validation.
7.6
CVE-2026-21367 - Buffer Over-read in WLAN Firmware
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.