First published: Wed Oct 06 2021(Updated: )
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos | ||
Samsung mobile devices | ||
All of | ||
Any of | ||
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos |
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25487 refers to an out-of-bounds read vulnerability in Samsung mobile devices.
The vulnerability occurs due to a lack of boundary checking of a buffer in the modem interface driver.
The vulnerability can be exploited to execute remote code by dereferencing an invalid function pointer.
Samsung mobile devices are affected by this vulnerability.
Ensure that you install the security update provided by Samsung.