CVE-2021-25338: Input Validation
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25338?
CVE-2021-25338 is a vulnerability that allows an attacker, given a compromised kernel, to write certain parts of the RKP EL2 memory region on Samsung mobile devices prior to SMR Mar-2021 Release 1.
What is the severity of CVE-2021-25338?
CVE-2021-25338 has a severity rating of 5.2, which is considered medium.
Is Google Android 10.0 affected by CVE-2021-25338?
Yes, Google Android 10.0 is affected by CVE-2021-25338.
Is Google Android 11.0 affected by CVE-2021-25338?
Yes, Google Android 11.0 is affected by CVE-2021-25338.
Is the Samsung Exynos 9830 vulnerable to CVE-2021-25338?
No, the Samsung Exynos 9830 is not vulnerable to CVE-2021-25338.
How can I fix CVE-2021-25338?
To fix CVE-2021-25338, users should install the SMR Mar-2021 Release 1 security update provided by Samsung for their mobile devices.