Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NSamsung Android
OSSamsung10.011.08.19.0
CISA KEV — detailsi
- Vendori
- Samsung
- Producti
- Mobile Devices
- Added to KEVi
- June 29, 2023
- Remediation deadline (US Federal)i
- July 20, 2023(overdue)
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.
Related vulnerabilities
Path Traversal w Samsung Galaxy Themes Service — dostęp do plików systemowych
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execu...
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execu...
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inope...
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers...