ZeroHour

CVE-2021-25489

KEVmass

Format String Kernel Panic DoS in Samsung Mobile Modem Interface Driver

CISA: Samsung Mobile Devices Improper Input Validation Vulnerability

CVSS 3.1
5.5 medium
EPSS
<1%p43
Published
()
KEV added
AI analysis

CVE-2021-25489 is a format string vulnerability (CWE-134, from missing input validation, CWE-20) in the modem interface driver of Samsung mobile devices running Android. It is triggered locally by an app or process that has already gained radio (phone) permission, which can send crafted input to the modem interface driver without proper validation. The result is a format string bug that causes a kernel panic — a crash of the device — with no confidentiality or integrity impact and no indication of code execution or privilege escalation, consistent with the CVSS 3.1 score of 5.5 (AV:L/PR:L, availability impact high). All Samsung mobile devices that have not applied the October 2021 Security Maintenance Release (SMR Oct-2021 Release 1) or later are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, indicating active exploitation, though no public proof-of-concept is known and ransomware use is listed as unknown.

What to do: Update affected Samsung devices to the SMR Oct-2021 Release 1 security maintenance release or a later one (check the Android security patch level under Settings > Software update), per CISA's required action to apply vendor updates or discontinue use of unpatched devices. Enterprise fleet administrators should audit device patch levels and prioritize updating anything older than October 2021. Because exploitation requires local access with radio permission and yields a crash rather than code execution, exposure to remote attackers is limited, but the KEV listing makes patching mandatory for federal and compliance-driven environments.

Affected
Samsung Mobile Devices (Android)prior to SMR Oct-2021 Release 1
Estimated exposure
masshundreds of millions of devices (Samsung's global Android install base; all devices below the Oct-2021 SMR patch level are affected, including models no longer… — Samsung is the world's largest Android vendor with a multi-billion-device installed base, and the vulnerable range covers every device not yet on the October 2021 or later security patch level, so plausibly affected devices far exceed one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-20, CWE-134
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news