CVE-2026-33970: Null Pointer Dereference

Published Sep 14, 2026
·
Updated

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.

Affected Software

18 affected components
Samsung Mobile Processor NR RRC and L2
Samsung Wearable Processor NR RRC and L2
Samsung Modem Exynos 850 NR RRC and L2
Samsung Modem Exynos 1080 NR RRC and L2
Samsung Modem Exynos 2100 NR RRC and L2
Samsung Modem Exynos 1280 NR RRC and L2
Samsung Modem Exynos 2200 NR RRC and L2
Samsung Modem Exynos 1330 NR RRC and L2
Samsung Modem Exynos 1380 NR RRC and L2
Samsung Modem Exynos 1480 NR RRC and L2
Samsung Modem Exynos 2400 NR RRC and L2
Samsung Modem Exynos 1580 NR RRC and L2
Samsung Modem Exynos 2500 NR RRC and L2
Samsung Modem Exynos 1680 NR RRC and L2
Samsung Modem W920 NR RRC and L2
Samsung Modem W930 NR RRC and L2
Samsung Modem W1000 NR RRC and L2
Samsung Modem 5410 NR RRC and L2

Event History

Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What would an attacker need to send to trigger the issue?

The issue is triggered by a malformed RRC Reconfiguration message processed by the 5G baseband. The supplied vector indicates network access, high attack complexity, low privileges required, and no user interaction.

2

What is the expected impact if exploitation succeeds?

The reported impact is availability only, caused by a NULL pointer dereference. Confidentiality and integrity impacts are listed as none, while availability impact is low.

3

Which hardware families are identified as affected?

The advisory identifies Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410 products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203