PT-2025-2751 · Samsung · Exynos 1280+6

Chao Ma

·

Published

2025-01-13

·

Updated

2025-01-14

·

CVE-2024-46919

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Mobile Processor Exynos versions 980 through 9825 Samsung Mobile Processor Exynos versions 990 Samsung Mobile Processor Exynos versions 850 Samsung Mobile Processor Exynos versions 1080 Samsung Mobile Processor Exynos versions 2100 Samsung Mobile Processor Exynos versions 1280
Description: An issue was discovered in Samsung Mobile Processor Exynos. The lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.
Recommendations: For Samsung Mobile Processor Exynos versions 980 through 9825, consider disabling the loadOutputBuffers function until a patch is available. For Samsung Mobile Processor Exynos version 990, restrict access to the vulnerable module to minimize the risk of exploitation. For Samsung Mobile Processor Exynos version 850, avoid using the vulnerable function until the issue is resolved. For Samsung Mobile Processor Exynos version 1080, consider applying configuration changes to mitigate the risk. For Samsung Mobile Processor Exynos version 2100, restrict the use of the vulnerable component to minimize the risk of exploitation. For Samsung Mobile Processor Exynos version 1280, consider disabling the vulnerable function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-46919

Affected Products

Exynos 1080
Exynos 1280
Exynos 2100
Exynos 850
Exynos 980
Exynos 9825
Exynos 990