ZeroHour

CVE-2021-25372

KEVmass

Out-of-Bounds Memory Access in Samsung Android DSP Driver

CISA: Samsung Mobile Devices Improper Boundary Check Vulnerability

CVSS 3.1
6.7 medium
EPSS
<1%p55
Published
()
KEV added
AI analysis

CVE-2021-25372 is an improper boundary check in the DSP (Digital Signal Processor) driver on Samsung mobile devices, which allows an out-of-bounds memory access when processing malformed inputs. The flaw is triggered locally on affected Samsung devices running a security patch level older than the March 2021 Samsung Maintenance Release (SMR Mar-2021 Release 1). A successful exploit yields high impact to confidentiality, integrity, and availability on the device (memory corruption class bug, CWE-787), and given its local attack vector it is most plausibly used as a step in a broader exploit chain rather than a remote, standalone attack. All Samsung Android smartphones and tablets that have not received the March 2021 (or later) security update are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-29, confirming it is being actively exploited in the wild, though details of specific ransomware or campaign use are unknown.

What to do: Update affected Samsung devices to the SMR Mar-2021 Release 1 security patch (Android security patch level 2021-03-01) or any later monthly release, per Samsung's instructions; this is the required action listed in CISA's KEV catalog. Fleet managers should check device patch levels via Settings > About phone > Software information > Android security patch version and treat any device below 2021-03-01 as vulnerable. Because the bug is locally exploitable and actively exploited, prioritize patching devices used by high-risk users and verify no exploit chain relyed on unpatched DSP drivers.

Affected
Samsung Mobile Devices (Android, DSP driver)All devices with a security patch level prior to SMR Mar-2021 Release 1 (i.e., Android security patch before 2021-03)
Estimated exposure
masshundreds of millions of Samsung Galaxy devices shipped with pre-March-2021 patch levels; the number still running unpatched firmware today is unknown but… — Samsung is the world's largest or second-largest Android vendor with billions of cumulative Galaxy device shipments, so the pre-March-2021 installed base is enormous, though routine over-the-air updates since March 2021 have likely patched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-787, CWE-703
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news