Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2021-25370
HistoryMar 26, 2021 - 6:23 p.m.

CVE-2021-25370

2021-03-2618:23:25
Samsung Mobile
www.cve.org
7
implementation
file descriptor
memory corruption
kernel panic
dpu driver

CVSS3

6.1

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

57.8%

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

CNA Affected

[
  {
    "product": "Samsung Mobile Devices",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "SMR Mar-2021 Release 1",
        "status": "affected",
        "version": "Selected O(8.X), P(9.0), Q(10.0), R(11.0) ",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

57.8%