PT-2024-7506 · Samsung · Samsung Exynos
Xingyu Jin
·
Published
2024-10-07
·
Updated
2025-10-29
·
CVE-2024-44068
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Exynos versions 9820 through 9825
Samsung Exynos versions 980 through 990
Samsung Exynos version 850
Samsung Exynos version W920
Description
The issue is related to a use-after-free vulnerability in the m2m scaler driver of Samsung Mobile Processor and Wearable Processor Exynos models. This vulnerability leads to privilege escalation. The vulnerability is being exploited in the wild, allowing attackers to execute arbitrary code and escalate privileges on affected devices. The estimated number of potentially affected devices is not specified.
Recommendations
For Samsung Exynos versions 9820 through 9825, update to the latest security patch SMR-Oct-2024 to fix the vulnerability.
For Samsung Exynos versions 980 through 990, update to the latest security patch SMR-Oct-2024 to fix the vulnerability.
For Samsung Exynos version 850, update to the latest security patch SMR-Oct-2024 to fix the vulnerability.
For Samsung Exynos version W920, update to the latest security patch SMR-Oct-2024 to fix the vulnerability.
As a temporary workaround, consider restricting access to the vulnerable m2m scaler driver until a patch is available.
Fix
LPE
RCE
Resource Exhaustion
Use After Free
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Exynos