CVE-2024-27373: Input Validation
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsinanconfiggetnlparams(), there is no input validation check on discattr->meshidlen coming from userspace, which can lead to a heap overwrite.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27373?
CVE-2024-27373 has been classified as a high severity vulnerability due to its potential for heap overwrite.
How does CVE-2024-27373 affect Samsung Mobile Processors?
CVE-2024-27373 affects Samsung Mobile Processors Exynos 980, 850, 1280, 1380, and 1330 by allowing unvalidated input which may lead to heap corruption.
How do I fix CVE-2024-27373?
To mitigate CVE-2024-27373, ensure that your device firmware is updated to a patched version as provided by Samsung.
What versions of firmware are affected by CVE-2024-27373?
CVE-2024-27373 affects various firmware versions of Samsung Exynos processors including Exynos 980, 850, 1280, 1380, and 1330.
Is there a workaround for CVE-2024-27373 until a fix is applied?
Currently, there are no specific workarounds documented for CVE-2024-27373, so updating the firmware is the recommended course of action.