Junglewise Threat Intelligence

CVE-2021-25487: Samsung Mobile Devices Out-of-Bounds Read Vulnerability

CVE-2021-25487 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-06-29

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

Samsung mobile devices contain an out-of-bounds read vulnerability in the modem interface driver's set_skb_priv() function due to insufficient boundary checking. This flaw can lead to arbitrary code execution via the dereference of an invalid function pointer.

Affected products

  • Samsung Android 8.1, 9.0, 10.0, 11.0 prior to SMR Oct-2021 Release 1

Timeline

  • 2021-10-06: disclosed: NVD Published Date
  • 2021-10-01: patched: SMR Oct-2021 Release 1
  • 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-29: exploited: Reported as exploited in the wild per CISA KEV entry date

Related threats