NULL Pointer Dereference in Samsung Exynos Mobile Processors
CVE-2025-54334

7.5HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
4 November 2025

What is CVE-2025-54334?

A vulnerability exists in the NPU driver within Samsung's Exynos Mobile Processor series, notably affecting versions 1280, 2200, 1380, 1480, 2400, 1580, and 2500. This flaw involves a NULL Pointer Dereference in the __npu_vertex_bootup function, potentially leading to system instability or unexpected behavior. Users and administrators of affected devices should review security updates and best practices to mitigate potential risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.