CVE-2021-25370
KEVmassMemory corruption in Samsung mobile dpu driver causes kernel panic (CVE-2021-25370)
CISA: Samsung Mobile Devices Memory Corruption Vulnerability
An incorrect file descriptor handling implementation in the dpu (display) driver of Samsung mobile devices causes memory corruption that can crash the kernel. A local process with high privileges on the device can trigger the flaw, resulting in a kernel panic and loss of device availability. Per the CVSS score, there is no direct confidentiality or integrity impact; the attacker gains only a denial-of-service crash. Any Samsung mobile device running firmware released before the March 2021 Security Maintenance Release 1 (SMR Mar-2021 Release 1) is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-08, confirming active exploitation, and related reporting indicates a surveillance vendor exploited Samsung phone zero-days; ransomware use is unknown.
What to do: Update affected Samsung devices to the SMR Mar-2021 Release 1 security patch or later via the system/OTA update mechanism, and verify the installed Android security patch level is March 2021 or newer. For managed fleets, use MDM/UEM policy to enforce a minimum Android security patch level of Mar-2021 across Samsung endpoints. No workarounds are documented beyond patching; limiting high-privileged local code execution reduces trigger opportunities.
| Samsung mobile devices (Android, dpu kernel driver) | firmware prior to Samsung Security Maintenance Release (SMR) Mar-2021 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-416, CWE-703
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H