PT-2026-5915 · Samsung · Exynos 1080+10
Published
2026-02-03
·
Updated
2026-02-09
·
CVE-2025-58343
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Mobile Processor and Wearable Processor Exynos 980
Samsung Mobile Processor and Wearable Processor Exynos 850
Samsung Mobile Processor and Wearable Processor Exynos 1080
Samsung Mobile Processor and Wearable Processor Exynos 1280
Samsung Mobile Processor and Wearable Processor Exynos 1330
Samsung Mobile Processor and Wearable Processor Exynos 1380
Samsung Mobile Processor and Wearable Processor Exynos 1480
Samsung Mobile Processor and Wearable Processor Exynos 1580
Samsung Mobile Processor and Wearable Processor Exynos W920
Samsung Mobile Processor and Wearable Processor Exynos W930
Samsung Mobile Processor and Wearable Processor Exynos W1000
Description
An issue exists due to unbounded memory allocation via a large buffer in a
/proc/driver/unifi0/create tspec write operation, leading to kernel memory exhaustion. The /proc/driver/unifi0/create tspec is an API endpoint used for creating a traffic specification. The vulnerability occurs when a large buffer is written to this endpoint, causing the system to allocate an excessive amount of memory. This can lead to a denial-of-service condition as the kernel runs out of available memory. The variable buffer size within the create tspec function is not properly validated, allowing an attacker to control the amount of memory allocated.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 1480
Exynos 1580
Exynos 850
Exynos 980
Exynos W1000
Exynos W920
Exynos W930