MEDIUM

CVE-2021-25371

Samsung Android 2021-03-26 CVSS v3.1
CVSS
6.7
KEV

Description

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

Summary dbcve.org

A vulnerability in the DSP (Digital Signal Processor) driver allows attackers to load arbitrary ELF libraries into the DSP context. This could enable arbitrary code execution within the DSP environment, potentially leading to privilege escalation or code execution in a protected processing domain.

Mitigation

Update the DSP driver to SMR Mar-2021 Release 1 or later to remediate this vulnerability. If patching is not immediately possible, restrict access to the DSP driver interfaces and monitor for unusual ELF loading activity.

Weakness (CWE)

CWE-912

EPSS Score

0.8%
Probability of exploitation in next 30 days
54.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE