CVE-2021-25489
KEVmassFormat String Kernel Panic DoS in Samsung Mobile Modem Interface Driver
CISA: Samsung Mobile Devices Improper Input Validation Vulnerability
CVE-2021-25489 is a format string vulnerability (CWE-134, from missing input validation, CWE-20) in the modem interface driver of Samsung mobile devices running Android. It is triggered locally by an app or process that has already gained radio (phone) permission, which can send crafted input to the modem interface driver without proper validation. The result is a format string bug that causes a kernel panic — a crash of the device — with no confidentiality or integrity impact and no indication of code execution or privilege escalation, consistent with the CVSS 3.1 score of 5.5 (AV:L/PR:L, availability impact high). All Samsung mobile devices that have not applied the October 2021 Security Maintenance Release (SMR Oct-2021 Release 1) or later are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, indicating active exploitation, though no public proof-of-concept is known and ransomware use is listed as unknown.
What to do: Update affected Samsung devices to the SMR Oct-2021 Release 1 security maintenance release or a later one (check the Android security patch level under Settings > Software update), per CISA's required action to apply vendor updates or discontinue use of unpatched devices. Enterprise fleet administrators should audit device patch levels and prioritize updating anything older than October 2021. Because exploitation requires local access with radio permission and yields a crash rather than code execution, exposure to remote attackers is limited, but the KEV listing makes patching mandatory for federal and compliance-driven environments.
| Samsung Mobile Devices (Android) | prior to SMR Oct-2021 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-20, CWE-134
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H