CVE-2021-25396: Input Validation
Published Jun 11, 2021
·Updated
An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.
Affected Software
6 affected components
Google Android=10.0
Google Android=11.0
Samsung Exynos 2100
Samsung Exynos 980
Samsung Exynos 9820
Samsung Exynos 9830
Event History
Jun 11, 2021
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25396.
2
What is the severity of CVE-2021-25396?
The severity of CVE-2021-25396 is medium with a CVSS score of 6.7.
3
What is the affected software for CVE-2021-25396?
The affected software for CVE-2021-25396 includes Google Android 10.0 and 11.0.
4
What is the impact of CVE-2021-25396?
CVE-2021-25396 allows arbitrary memory write and code execution.
5
How can I fix CVE-2021-25396?
To fix CVE-2021-25396, apply the SMR MAY-2021 Release 1 for NPU firmware.