{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-21385",
  "revision": 1,
  "title": "Qualcomm chipsets — memory corruption in allocation alignment",
  "summary": "Multiple Qualcomm chipsets corrupt memory while handling alignment during memory allocation. The chipset bulletin gives no more detail than that, and the fix reaches devices through the March 2026 Android update.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01287,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-03-03",
    "prerequisites": "Not stated — neither the chipset bulletin nor the Android entry names an attack vector."
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "execution",
  "recommended_action": "Install the March 2026 Android security patch level or later; on devices past vendor support, plan replacement — the chipset fix will never reach them.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-21385",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-21385",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-21385",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21385",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html"
    },
    {
      "type": "vendor_advisory",
      "url": "https://source.android.com/docs/security/bulletin/2026/2026-03-01"
    }
  ],
  "published_at": "2026-03-02T17:16:29.207Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "qualcomm",
    "android",
    "chipset",
    "memory-corruption",
    "mobile",
    "kev"
  ]
}
