Skip to content
QualcommCVE-2026-21383

Cryptographic Issue when using a static initialization vector for AES-GCM key...

High7.1CVE-2026-21383 · Published Jul 6, 2026 · updated Jul 8, 2026

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

Qualcomm advisory

Affected versions

PackageAffectedFixed in
Snapdragon
Product
<= FastConnect 6900No fix yet
<= FastConnect 7800No fix yet
<= LeMans_AU_LGITNo fix yet
<= LeMansAUNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-323

More Qualcomm advisories

All Qualcomm
Advisory
Qualcomm Snapdragon: memory corruption
Medium5.3Jul 6
Qualcomm Snapdragon: memory corruption
High8.8Jul 6
Qualcomm Snapdragon: memory corruption
High7.8Jul 6
Qualcomm Snapdragon: memory corruption
Medium5.3Jul 6
Qualcomm Snapdragon: memory corruption
Medium5.3Jul 6
Qualcomm Snapdragon: memory corruption
Medium5.3Jul 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.