CVE-2021-25489: Samsung Mobile Devices Improper Input Validation Vulnerability
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
Other sources
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung mobile devicesto a version that resolves this vulnerability.Fixed in SMR Oct-2021 Release 1 - Compensating control
Discontinue use of affected Samsung mobile devices if updates (SMR Oct-2021 Release 1 or later) are unavailable
Event History
Frequently Asked Questions
What is the vulnerability ID for this Samsung mobile devices vulnerability?
The vulnerability ID for this Samsung mobile devices vulnerability is CVE-2021-25489.
What is the title of the vulnerability?
The title of the vulnerability is 'Samsung Mobile Devices Improper Input Validation Vulnerability'.
What is the description of the vulnerability?
The vulnerability involves an improper input validation vulnerability within the modem interface driver of Samsung mobile devices, which can result in a format string bug leading to kernel panic.
Which software is affected by this vulnerability?
The vulnerability affects Samsung mobile devices.
How can I learn more about this vulnerability?
You can learn more about this vulnerability by visiting the reference link provided: [Samsung Mobile Security Updates](https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10)