Junglewise Threat Intelligence

CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability

CVE-2021-25370 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2022-11-08

Technologies: Samsung Mobile Devices, Google Android. Vendors: Samsung, Google.

Executive brief

Samsung mobile devices using Mali GPUs contain an incorrect file descriptor handling implementation in the dpu driver. This flaw leads to memory corruption and kernel panic, and has been observed being chained with other vulnerabilities in the wild.

Affected products

  • Google Android 8.0, 8.1, 9.0, 10.0, 11.0
  • Samsung Android (SMR) Prior to SMR Mar-2021 Release 1

Timeline

  • 2021-03-26: disclosed: NVD Published Date
  • 2021-03-01: patched: SMR Mar-2021 Release 1
  • 2022-11-08: kev added: Added to CISA KEV catalog
  • 2022-11-08: exploited: Reported as exploited in the wild in advisory summary

Related threats