Executive brief
Samsung Exynos processors contain a double-free vulnerability in the Media Format Converter (MFC) encoder driver used for video encoding on mobile devices and wearables. Improper cleanup of memory references during error handling allows an attacker to corrupt kernel memory and potentially execute arbitrary code, affecting millions of smartphones and wearable devices globally.
Technical details
A double-free vulnerability exists in the Exynos MFC encoder driver due to improper cleanup of DMA buffer references during error handling. The vulnerability is rooted in the resource management logic of the MFC encoder, which fails to properly release memory references when an error occurs, allowing the same memory region to be freed twice. This can be triggered by applications with access to the MFC hardware encoder (typically through system APIs), leading to kernel memory corruption. An attacker can exploit this to achieve arbitrary code execution in the kernel context. Patches are available from Samsung for affected Exynos processors.
Affected products
- Samsung Exynos 850 all
- Samsung Exynos 1080 all
- Samsung Exynos 2100 all
- Samsung Exynos 1280 all
- Samsung Exynos 2200 all
- Samsung Exynos 1330 all
- Samsung Exynos 1380 all
- Samsung Exynos 1480 all
- Samsung Exynos 2400 all
- Samsung Exynos 1580 all
- Samsung Exynos 2500 all
- Samsung Exynos 2600 all
- Samsung Exynos 1680 all
- Samsung Exynos W920 all
- Samsung Exynos W930 all
- Samsung Exynos W1000 all
Timeline
- 2025-12-23: disclosed: CVE reported date
- 2026-09-14: advisory: Published on NVD