CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-58349

CVSS 9.1v3.1pub. 2026-04-06upd. 2026-07-24

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Incorrect handling of LTE MAC packets containing many MAC Control Elements (CEs) leads to baseband crashes.

🤖 AI Analysis
How it works

An attacker sends specially crafted LTE MAC packets containing an excessive number of MAC Control Elements (CEs). Improper handling of such packets in the L2 layer of the modem causes resource exhaustion (CWE-400 — Uncontrolled Resource Consumption), resulting in baseband software failure. The vulnerability requires no user interaction or prior authentication — the device only needs to be within the cellular network coverage.

Impact

An attacker can remotely cause a modem failure (baseband crash), resulting in loss of device connectivity to the cellular network (denial of service). According to the CVSS vector, high loss of confidentiality of data processed by the modem is also possible.

Mitigation & patch

Apply patches available from the manufacturer according to the references — update details available on the Samsung Semiconductor Product Security Updates page: https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-58349/

Who is affected

Samsung Mobile Processor, Wearable Processor and Modem from families: Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Samsung Exynos 1080

    HW
    Samsung
    all versions
  • Samsung Exynos 1080 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1280

    HW
    Samsung
    all versions
  • Samsung Exynos 1280 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1330

    HW
    Samsung
    all versions
  • Samsung Exynos 1330 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1380

    HW
    Samsung
    all versions
  • Samsung Exynos 1380 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1480

    HW
    Samsung
    all versions
  • Samsung Exynos 1480 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 1580

    HW
    Samsung
    all versions
  • Samsung Exynos 1580 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2100

    HW
    Samsung
    all versions
  • Samsung Exynos 2100 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2200

    HW
    Samsung
    all versions
  • Samsung Exynos 2200 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2400

    HW
    Samsung
    all versions
  • Samsung Exynos 2400 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 2500

    HW
    Samsung
    all versions
  • Samsung Exynos 2500 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 850

    HW
    Samsung
    all versions
  • Samsung Exynos 850 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 9110

    HW
    Samsung
    all versions
  • Samsung Exynos 9110 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 980

    HW
    Samsung
    all versions
  • Samsung Exynos 980 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos 990

    HW
    Samsung
    all versions
  • Samsung Exynos 990 Firmware

    OS
    Samsung
    all versions
  • Samsung Exynos Modem 5123

    HW
    Samsung
    all versions
  • Samsung Exynos Modem 5123 Firmware

    OS
    Samsung
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-62818CRITICAL9.8PL ✓same product

Out-of-bounds write w procesorach Samsung Exynos przy przetwarzaniu SMS TP-UD

CVE-2025-52908CRITICAL9.8PL ✓same product

Buffer overflow w sterowniku Wi-Fi Samsung Exynos przez błędną obsługę NL80211

CVE-2025-52909CRITICAL9.8PL ✓same product

Buffer overflow w sterowniku Wi-Fi Samsung Exynos przez NL80211

CVE-2025-54328CRITICAL10.0PL ✓same product

Stack-based Buffer Overflow w obsłudze SMS w procesorach Samsung Exynos

CVE-2025-27807CRITICAL9.1PL ✓same product

Out-of-bounds write w Samsung Exynos via błędne pakiety NAS