CVE-2021-25487: Samsung Mobile Devices Out-of-Bounds Read Vulnerability
Lack of boundary checking of a buffer in setskbpriv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
Other sources
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in setskbpriv(), leading to remote code execution by dereference of an invalid function pointer.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Samsung mobile devicesfrom your environment.Discontinue use of the product if updates are unavailable
Event History
Frequently Asked Questions
What is CVE-2021-25487?
CVE-2021-25487 refers to an out-of-bounds read vulnerability in Samsung mobile devices.
How does the out-of-bounds read vulnerability in Samsung mobile devices occur?
The vulnerability occurs due to a lack of boundary checking of a buffer in the modem interface driver.
What is the impact of CVE-2021-25487?
The vulnerability can be exploited to execute remote code by dereferencing an invalid function pointer.
Which devices are affected by the out-of-bounds read vulnerability?
Samsung mobile devices are affected by this vulnerability.
How can I stay protected from CVE-2021-25487?
Ensure that you install the security update provided by Samsung.