CVE-2025-22377: Medium severity samsung exynos 980 firmware vulnerability
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22377?
CVE-2025-22377 has been classified as a high severity vulnerability due to the potential for a heap-based out-of-bounds write.
How do I fix CVE-2025-22377?
To mitigate CVE-2025-22377, users should update their Samsung mobile processors and modems to the latest firmware version provided by Samsung.
Which devices are affected by CVE-2025-22377?
CVE-2025-22377 affects various Samsung Exynos processors and modems, including Exynos 980, 990, 850, 1080, 2100, and others.
What impact does CVE-2025-22377 have on my device's security?
CVE-2025-22377 can potentially allow attackers to execute arbitrary code, compromising the security and functionality of affected devices.
Is there a workaround for CVE-2025-22377 if I cannot update my device?
Currently, the best course of action for CVE-2025-22377 is to apply the firmware updates, as no specific workaround has been recommended.