Executive brief
Samsung Exynos mobile processors contain a NULL pointer dereference vulnerability in the Neural Processing Unit (NPU) firmware that can cause the processor to crash and become unavailable. An attacker who can trigger specific NPU operations could force a denial of service, disrupting device functionality and potentially causing data loss during critical operations.
Technical details
A NULL pointer dereference exists in the __pilot_parsing_ncp() function within the NPU firmware of affected Exynos processors, where the session->ncp_hdr_buf pointer is not properly validated before use. The vulnerability is triggered through malformed or specially crafted NCP (Neural Compute Protocol) input during parsing, causing an unhandled exception. The affected component is the NPU (Neural Processing Unit) firmware, which is accessible to code running on the processor with appropriate capabilities. Successful exploitation results in a denial of service as the NPU crashes or the entire SoC may need to be reset. A fix is available from Samsung through firmware updates for affected Exynos generations.
Affected products
- Samsung Exynos 1280 all
- Samsung Exynos 2200 all
- Samsung Exynos 1380 all
- Samsung Exynos 1480 all
- Samsung Exynos 2400 all
- Samsung Exynos 1580 all
- Samsung Exynos 2500 all
Timeline
- 2025-09-29: disclosed
- 2026-03-03: advisory