PT-2024-21873 · Samsung · Exynos

Jiayy

·

Published

2024-07-09

·

Updated

2024-08-01

·

CVE-2024-27386

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Mobile Processor Exynos versions 1380 through 1480
Description A vulnerability was discovered in the slsi handle nan rx event log ind function related to no input validation check on tag len for tx coming from userspace, which can lead to heap overwrite.
Recommendations For Samsung Mobile Processor Exynos versions 1380 through 1480, consider disabling the slsi handle nan rx event log ind function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-27386

Affected Products

Exynos