PT-2024-7506 · Samsung · Samsung Exynos

Xingyu Jin

·

Published

2024-10-07

·

Updated

2025-10-29

·

CVE-2024-44068

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Exynos versions 9820 through 9825 Samsung Exynos versions 980 through 990 Samsung Exynos version 850 Samsung Exynos version W920
Description The issue is related to a use-after-free vulnerability in the m2m scaler driver of Samsung Mobile Processor and Wearable Processor Exynos models. This vulnerability leads to privilege escalation. The vulnerability is being exploited in the wild, allowing attackers to execute arbitrary code and escalate privileges on affected devices. The estimated number of potentially affected devices is not specified.
Recommendations For Samsung Exynos versions 9820 through 9825, update to the latest security patch SMR-Oct-2024 to fix the vulnerability. For Samsung Exynos versions 980 through 990, update to the latest security patch SMR-Oct-2024 to fix the vulnerability. For Samsung Exynos version 850, update to the latest security patch SMR-Oct-2024 to fix the vulnerability. For Samsung Exynos version W920, update to the latest security patch SMR-Oct-2024 to fix the vulnerability. As a temporary workaround, consider restricting access to the vulnerable m2m scaler driver until a patch is available.

Fix

LPE

RCE

Resource Exhaustion

Use After Free

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-08894
BDU:2025-13730
CVE-2024-44068

Affected Products

Samsung Exynos