Junglewise Threat Intelligence

CVE-2023-37366: Samsung Exynos denial of service in Shannon SM Task

CVE-2023-37366 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 9110, Samsung Exynos 1280, Samsung Exynos 2200, Samsung Exynos 1380, Samsung Exynos W920, Samsung Exynos Modem 5123, Samsung Exynos 980, Samsung Exynos 2100, Samsung Exynos 1330, Samsung Exynos Modem 5300, Samsung Exynos 850, Samsung Exynos 1080. Vendors: Samsung.

Executive brief

Samsung's Exynos processor family is used across millions of mobile devices and vehicles. A flaw in the Shannon SM Task component can be triggered via a malformed message to enter an infinite loop, causing the service to hang and become unresponsive. This results in a denial of service, potentially affecting device functionality until the processor is rebooted.

Technical details

The vulnerability is an improper handling of a loop with an unreachable exit condition in the Shannon SM Task component of Samsung Exynos processors. An attacker can send a specially crafted SM message that causes the task to enter an infinite loop, preventing graceful termination of the service. The attack requires the ability to send malformed messages to the SM Task, and successful exploitation results in a denial of service condition. Samsung has indicated patches are available, though availability varies by vendor implementation.

Affected products

  • Samsung Exynos 9810 all
  • Samsung Exynos 9610 all
  • Samsung Exynos 9820 all
  • Samsung Exynos 980 all
  • Samsung Exynos 850 all
  • Samsung Exynos 1080 all
  • Samsung Exynos 2100 all
  • Samsung Exynos 2200 all
  • Samsung Exynos 1280 all
  • Samsung Exynos 1380 all
  • Samsung Exynos 1330 all
  • Samsung Exynos 9110 all
  • Samsung Exynos W920 all
  • Samsung Exynos Modem 5123 all
  • Samsung Exynos Modem 5300 all
  • Samsung Exynos Auto T5123 all

Timeline

  • 2023-04-28: disclosed
  • 2026-09-14: advisory

References

Related threats