CVE-2025-58340: Medium severity Samsung Mobile Processor and Wearable Processor Exynos vulnerability
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/senddelts write operation, leading to kernel memory exhaustion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58340?
CVE-2025-58340 is a critical vulnerability due to unbounded memory allocation in the Wi-Fi driver of specific Samsung processors.
How do I fix CVE-2025-58340?
To fix CVE-2025-58340, you should update the firmware of your affected Samsung Mobile or Wearable processors to the latest version provided by Samsung.
Which devices are affected by CVE-2025-58340?
CVE-2025-58340 affects Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000.
What risks does CVE-2025-58340 pose to users?
CVE-2025-58340 can potentially lead to kernel memory corruption, which may result in system crashes or unauthorized access to sensitive data.
Is there a workaround for CVE-2025-58340 until a patch is applied?
Currently, there is no publicly available workaround for CVE-2025-58340, and users are recommended to apply the firmware update as soon as it is available.