CVE-2021-25395: Samsung Mobile Devices Race Condition Vulnerability
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
Other sources
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the product if updates are unavailable
Event History
Frequently Asked Questions
What is CVE-2021-25395?
CVE-2021-25395 is a race condition vulnerability found in Samsung mobile devices' MFC charger driver.
What is the severity of CVE-2021-25395?
The severity of CVE-2021-25395 is not mentioned in the provided information.
How can the race condition vulnerability in CVE-2021-25395 be exploited?
The race condition vulnerability in CVE-2021-25395 can be exploited by compromising the radio privilege and leveraging the use-after-free vulnerability.
What software is affected by CVE-2021-25395?
Samsung mobile devices are affected by the race condition vulnerability CVE-2021-25395.
How can I learn more about CVE-2021-25395?
You can check the reference link provided to learn more about CVE-2021-25395.