CRITICAL
CVE-2025-21043
CVSS
9.8
KEV
Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
Summary dbcve.org
An out-of-bounds write vulnerability exists in Samsung's libimagecodec.quram.so image codec library. The flaw allows remote attackers to achieve arbitrary code execution, likely by tricking users into processing specially crafted malicious image files that trigger the memory corruption.
Mitigation
Apply the SMR Sep-2025 Release 1 security update or later, which contains the patched version of libimagecodec.quram.so. Until patched, avoid processing untrusted image sources.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
1.91%
Probability of exploitation in next 30 days
78.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.