CVE-2021-25487
KEVmassOut-of-Bounds Read in Samsung Modem Interface Driver Enables Arbitrary Code Execution
CISA: Samsung Mobile Devices Out-of-Bounds Read Vulnerability
CVE-2021-25487 is an out-of-bounds read (CWE-125) in the set_skb_priv() function of the modem interface driver on Samsung mobile devices, caused by missing boundary checking of a buffer. The flaw is triggered when the driver processes data without validating buffer bounds, and per the CVSS vector exploitation is local (AV:L), requiring low privileges and no user interaction. By dereferencing an invalid function pointer, the attacker achieves arbitrary code execution with high impact on confidentiality, integrity, and availability, effectively enabling compromise of the affected phone or tablet. Affected products are Samsung mobile devices (Android) running firmware prior to the Samsung Security Maintenance Release (SMR) Oct-2021 Release 1. The flaw is actively exploited in the wild per its addition to the CISA Known Exploited Vulnerabilities catalog on 2023-06-29; no public PoC is known and ransomware use is unknown.
What to do: Apply Samsung's SMR Oct-2021 Release 1 or any later security maintenance release via Settings > Software update or through your enterprise MDM/UEM, per CISA's required action for KEV entries. Verify device security patch level is October 2021 or newer, and prioritize any Samsung handsets still below that patch level given confirmed active exploitation.
| Samsung Mobile devices (Android) | Device firmware prior to Samsung SMR Oct-2021 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H