First published: Wed Nov 09 2022(Updated: )
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Exynos Firmware | ||
Samsung Exynos |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39881 is an improper input validation vulnerability that affects Exynos modems prior to SMR Sep-2022 Release, allowing a remote attacker to read out of bounds memory.
The Samsung Exynos Firmware is affected by CVE-2022-39881.
CVE-2022-39881 has a severity rating of 9.1, which is classified as critical.
An attacker can exploit CVE-2022-39881 by sending a specially crafted SIB12 PDU to the vulnerable Exynos modem, which can lead to reading out of bounds memory.
Yes, the fix for CVE-2022-39881 is included in the SMR Sep-2022 Release from Samsung.