CVE-2024-27379: Input Validation
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsinansubscribegetnlparams(), there is no input validation check on halreq->numintfaddrpresent coming from userspace, which can lead to a heap overwrite.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27379?
CVE-2024-27379 is considered a high-severity vulnerability due to its potential for heap overwriting.
How do I fix CVE-2024-27379?
To mitigate CVE-2024-27379, it is recommended to update to the latest firmware version provided by Samsung for affected Exynos processors.
Which devices are affected by CVE-2024-27379?
CVE-2024-27379 affects Samsung Mobile Processors Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330.
What is the nature of the vulnerability in CVE-2024-27379?
CVE-2024-27379 is caused by a lack of input validation in the function slsi_nan_subscribe_get_nl_params(), leading to potential heap overwrites.
Can CVE-2024-27379 be exploited remotely?
CVE-2024-27379 may allow exploitation through userspace input, making it a concern for remote attacks depending on the application context.