HIGH
CVE-2021-25487
CVSS
7.8
KEV
Description
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
Summary dbcve.org
Out-of-bounds read vulnerability in the set_skb_priv() function of a modem interface driver due to missing boundary checks on a buffer. The OOB read allows dereferencing an invalid function pointer, leading to arbitrary code execution. Affected devices are those running firmware prior to the SMR Oct-2021 Release 1.
Mitigation
Update device firmware to SMR Oct-2021 Release 1 or later, which contains proper boundary checking in the modem interface driver.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.64%
Probability of exploitation in next 30 days
48.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.