CVE-2026-33970: Null Pointer Dereference
An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.
Affected Software
Event History
Frequently Asked Questions
What would an attacker need to send to trigger the issue?
The issue is triggered by a malformed RRC Reconfiguration message processed by the 5G baseband. The supplied vector indicates network access, high attack complexity, low privileges required, and no user interaction.
What is the expected impact if exploitation succeeds?
The reported impact is availability only, caused by a NULL pointer dereference. Confidentiality and integrity impacts are listed as none, while availability impact is low.
Which hardware families are identified as affected?
The advisory identifies Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410 products.