PT-2025-2752 · Samsung · Exynos 990+6
Chao Ma
·
Published
2025-01-13
·
Updated
2025-01-14
·
CVE-2024-46920
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Samsung Mobile Processor Exynos versions 980 through 9825
Samsung Mobile Processor Exynos versions 990
Samsung Mobile Processor Exynos versions 850
Samsung Mobile Processor Exynos versions 1080
Samsung Mobile Processor Exynos versions 2100
Samsung Mobile Processor Exynos versions 1280
Description:
An issue was discovered in Samsung Mobile Processor Exynos. The lack of a length check leads to a stack out-of-bounds write at
loadInputBuffers.Recommendations:
For Samsung Mobile Processor Exynos versions 980 through 9825, consider disabling the
loadInputBuffers function until a patch is available.
For Samsung Mobile Processor Exynos version 990, restrict access to the vulnerable module to minimize the risk of exploitation.
For Samsung Mobile Processor Exynos version 850, avoid using the vulnerable parameter in the affected API endpoint until the issue is resolved.
For Samsung Mobile Processor Exynos versions 1080, 2100, and 1280, as a temporary workaround, consider restricting the use of the vulnerable component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exynos 1080
Exynos 1280
Exynos 2100
Exynos 850
Exynos 980
Exynos 9825
Exynos 990