Input Validation Vulnerability in Samsung Mobile Processors
CVE-2024-27371

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 June 2024

Summary

A security issue in specific Samsung Exynos mobile processors has been identified, where the function slsi_nan_followup_get_nl_params() does not perform adequate input validation on the service_specific_info_len parameter sourced from userspace. This lack of validation may result in a heap overwrite, potentially allowing attackers to execute arbitrary code or escalate privileges. The affected processors include Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330, necessitating prompt attention to mitigate risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.