CVE-2021-25372: Samsung Mobile Devices Improper Boundary Check Vulnerability

Published Mar 26, 2021
·
Updated

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

Other sources

Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.

CISA

Affected Software

13 affected components
Samsung Mobile Devices
Google Android=10.0
Google Android=11.0
Samsung Exynos 2100
Samsung Exynos 980
Samsung Exynos 9830
All of the following
Any of the following
Samsung android=10.0-smr-feb-2021-r1
Samsung android=10.0-smr-jan-2021-r1
Samsung android=11.0-smr-feb-2021-r1
Samsung android=11.0-smr-jan-2021-r1
Any of the following
Samsung Exynos 2100
Samsung Exynos 980
Samsung Exynos 9830

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Discontinue use of the affected Samsung mobile devices if vendor updates are unavailable.

Event History

Mar 26, 2021
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 2023
Known Exploited
via CISA·12:00 AM
Oct 14, 58448
Event
06:05 PM

Frequently Asked Questions

1

What is CVE-2021-25372?

CVE-2021-25372 refers to an improper boundary check vulnerability found in Samsung mobile devices.

2

How does CVE-2021-25372 impact Samsung mobile devices?

CVE-2021-25372 allows for out-of-bounds memory access on Samsung mobile devices.

3

Which Samsung mobile devices are affected by CVE-2021-25372?

CVE-2021-25372 affects all Samsung mobile devices.

4

What is the severity of CVE-2021-25372?

The severity of CVE-2021-25372 is not specified.

5

How can I fix CVE-2021-25372 on my Samsung mobile device?

To fix CVE-2021-25372 on your Samsung mobile device, it is recommended to install the security update provided by Samsung.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203