Heap Overwrite Vulnerability in Samsung Exynos Mobile Processors
CVE-2024-27372

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 June 2024

Summary

A vulnerability has been identified in Samsung's Exynos mobile processors, specifically affecting the Exynos 980, 850, 1280, 1380, and 1330. The issue arises in the slsi_nan_config_get_nl_params() function, where an absence of input validation checks on the incoming variable disc_attr->infrastructure_ssid_len from user space can lead to improper handling of memory allocation. This oversight may allow for heap overflow exploitation, potentially compromising system integrity and security. Users and developers are advised to review Samsung's security updates for necessary mitigations.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.