PT-2021-16677 · Samsung · Samsung Mobile Devices

Published

2021-10-06

·

Updated

2025-10-30

·

CVE-2021-25487

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Samsung Mobile Devices versions prior to SMR Oct-2021 Release 1
Description: The issue is related to a lack of boundary checking of a buffer in the set skb priv() function of the modem interface driver. This allows an out-of-bounds read, which can result in arbitrary code execution by dereferencing an invalid function pointer.
Recommendations: For versions prior to SMR Oct-2021 Release 1, update to SMR Oct-2021 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the modem interface driver to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2021-25487

Affected Products

Samsung Mobile Devices