HIGH

CVE-2021-25487

Samsung Android 2021-10-06 CVSS v3.1
CVSS
7.8
KEV

Description

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

Summary dbcve.org

Out-of-bounds read vulnerability in the set_skb_priv() function of a modem interface driver due to missing boundary checks on a buffer. The OOB read allows dereferencing an invalid function pointer, leading to arbitrary code execution. Affected devices are those running firmware prior to the SMR Oct-2021 Release 1.

Mitigation

Update device firmware to SMR Oct-2021 Release 1 or later, which contains proper boundary checking in the modem interface driver.

Weakness (CWE)

CWE-125 Out-of-bounds Read

EPSS Score

0.64%
Probability of exploitation in next 30 days
48.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE