CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
Other sources
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung mobile devices (dpu driver / SMR)to a version that resolves this vulnerability.Fixed in SMR Mar-2021 Release 1
Event History
Frequently Asked Questions
What is CVE-2021-25370?
CVE-2021-25370 is a memory corruption vulnerability found in Samsung mobile devices using Mali GPU.
How does CVE-2021-25370 affect Samsung mobile devices?
CVE-2021-25370 can lead to memory corruption and kernel panic on Samsung mobile devices using Mali GPU.
What is the severity of CVE-2021-25370?
CVE-2021-25370 has a severity rating of 4.4 (medium).
Which versions of Android are affected by CVE-2021-25370?
CVE-2021-25370 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
How can I fix CVE-2021-25370?
To mitigate CVE-2021-25370, make sure to update your Samsung mobile device to the latest security patch provided by Samsung.