First published: Wed Oct 06 2021(Updated: )
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos | ||
Samsung mobile devices | ||
All of | ||
Any of | ||
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos |
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Samsung mobile devices vulnerability is CVE-2021-25489.
The title of the vulnerability is 'Samsung Mobile Devices Improper Input Validation Vulnerability'.
The vulnerability involves an improper input validation vulnerability within the modem interface driver of Samsung mobile devices, which can result in a format string bug leading to kernel panic.
The vulnerability affects Samsung mobile devices.
You can learn more about this vulnerability by visiting the reference link provided: [Samsung Mobile Security Updates](https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10)