Heap Overflow Vulnerability in Samsung Mobile Processors
CVE-2024-27377

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 June 2024

Summary

A vulnerability exists in select Samsung Mobile Processor models, specifically Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. The issue arises from a lack of input validation in the function slsi_nan_get_security_info_nl(), which processes user input. As a result, an attacker could exploit this flaw to manipulate memory allocation, potentially leading to a heap overwrite. This can adversely affect the operation of the affected devices, compromising their security and stability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.