CVE-2024-27385
—CVSS 3.1
6.7 medium
EPSS
<1%p14
Published
()
Modified
Description
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.
- Vendors
- samsung
- Products
- exynos 1380 firmware, exynos 1480 firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.