CVE-2022-39881: Input Validation
Published Nov 9, 2022
·Updated
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.
Affected Software
2 affected components
Samsung Exynos Firmware
Samsung Exynos
Event History
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39881?
CVE-2022-39881 is an improper input validation vulnerability that affects Exynos modems prior to SMR Sep-2022 Release, allowing a remote attacker to read out of bounds memory.
2
What software is affected by CVE-2022-39881?
The Samsung Exynos Firmware is affected by CVE-2022-39881.
3
What is the severity of CVE-2022-39881?
CVE-2022-39881 has a severity rating of 9.1, which is classified as critical.
4
How can an attacker exploit CVE-2022-39881?
An attacker can exploit CVE-2022-39881 by sending a specially crafted SIB12 PDU to the vulnerable Exynos modem, which can lead to reading out of bounds memory.
5
Is there a fix for CVE-2022-39881?
Yes, the fix for CVE-2022-39881 is included in the SMR Sep-2022 Release from Samsung.