First published: Thu Sep 09 2021(Updated: )
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos 2100 | ||
Samsung Exynos 980 | ||
Samsung Exynos 9830 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25457 is an improper input validation vulnerability in the DSP driver prior to SMR Sep-2021 Release 1, which allows local attackers to get a limited kernel memory information.
Google Android 10.0 and 11.0 are affected by CVE-2021-25457.
CVE-2021-25457 has a severity rating of medium (3.3).
To fix CVE-2021-25457, update to the SMR Sep-2021 Release 1 or apply the security update provided by Samsung.
You can find more information about CVE-2021-25457 at the following link: [https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=9](https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=9)