Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2021-25487

Samsung Mobile Devices Out-of-Bounds Read Vulnerability

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

cat cve-2021-25487.json
Vendor
Samsung
Product
Mobile Devices
CVSS
7.3
EPSS (exploit probability)
0.6%
Status
kev
CISA patch-by (BOD 22-01)
Published

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2023-06-29. Required action per CISA: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Due date: 2023-07-20.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.