Junglewise Threat Intelligence

CVE-2021-25372: Samsung Mobile Devices Improper Boundary Check Vulnerability

CVE-2021-25372 · Severity: critical · CVSS 6.7 · Exploited in the wild · Published 2023-06-29

Technologies: Samsung Mobile Devices, Samsung Exynos 980, Samsung Exynos 2100. Vendors: Samsung.

Executive brief

Samsung mobile devices contain an improper boundary check vulnerability within the DSP driver. This flaw allows for out-of-bounds memory access, potentially leading to memory corruption or unauthorized access.

Affected products

  • Samsung DSP Driver Prior to SMR Mar-2021 Release 1
  • Samsung Exynos 2100
  • Samsung Exynos 980
  • Samsung Exynos 9830

Timeline

  • 2021-03-26: disclosed
  • 2021-03-01: patched: SMR Mar-2021 Release 1
  • 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-29: exploited

Related threats