Executive brief
Samsung's Exynos 5G baseband processors power mobile devices and wearables by handling cellular communications. A vulnerability in the RRC (Radio Resource Control) message handler can cause the baseband processor to crash when processing a malformed 5G configuration message, resulting in loss of connectivity and potential denial of service.
Technical details
A NULL pointer dereference (CWE-476) vulnerability exists in the NR RRC and L2 components of Samsung's Exynos 5G baseband. The vulnerability is triggered by processing a malformed RRC Reconfiguration message that causes a NULL pointer to be dereferenced, leading to a crash of the baseband processor. An attacker with network access to the 5G radio link can send a crafted RRC Reconfiguration message to trigger the crash. This results in denial of service (loss of cellular connectivity) but does not allow code execution or access to user data. Samsung has issued patches for affected Exynos processor and modem variants.
Affected products
- Samsung Exynos 850
- Samsung Exynos 1080
- Samsung Exynos 2100
- Samsung Exynos 1280
- Samsung Exynos 2200
- Samsung Exynos 1330
- Samsung Exynos 1380
- Samsung Exynos 1480
- Samsung Exynos 2400
- Samsung Exynos 1580
- Samsung Exynos 2500
- Samsung Exynos 1680
- Samsung Exynos W920
- Samsung Exynos W930
- Samsung Exynos W1000
- Samsung Modem 5410
Timeline
- 2026-09-14: disclosed
- 2025-12-24: advisory: Reported date per Samsung security advisory