PT-2025-9986 · Samsung · Exynos

Published

2025-03-06

·

Updated

2025-03-07

·

CVE-2024-52924

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400
Description The issue is related to a lack of boundary check during the decoding of Registration Accept messages, which can lead to out-of-bounds writes on the stack.
Recommendations For Samsung Mobile Processor, Wearable Processor, and Modem Exynos versions 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, consider restricting the decoding of Registration Accept messages to prevent out-of-bounds writes on the stack until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52924

Affected Products

Exynos