CVE-2021-25371
KEVmassArbitrary ELF library loading flaw in Samsung mobile DSP driver (CVE-2021-25371)
CISA: Samsung Mobile Devices Unspecified Vulnerability
CVE-2021-25371 is a vulnerability in the Digital Signal Processor (DSP) driver on Samsung mobile devices that, prior to the Samsung Mobile Security Release (SMR) Mar-2021 Release 1, allows attackers to load arbitrary ELF libraries inside the DSP. It is triggered locally, with the CVSS vector (AV:L, PR:H) indicating the attacker must already have local access with high privileges on the device. Successful exploitation lets the attacker run arbitrary library code within the DSP subsystem, with high impact on confidentiality, integrity, and availability. All Samsung mobile devices whose DSP driver has not been updated with the SMR Mar-2021 Release 1 (or later) are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, confirming active exploitation in the wild, though ransomware use is listed as unknown.
What to do: Update affected Samsung devices to the SMR Mar-2021 Release 1 or any later Samsung mobile security release via Settings > Software update, and verify the device's Android security patch level is March 2021 or newer. Organizations subject to CISA's KEV requirements must apply the vendor update, or discontinue use of unpatched devices, per the catalog's required action.
| Samsung Mobile Devices (Android) | DSP driver in all Samsung mobile devices prior to SMR Mar-2021 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-912
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H