CISA Known Exploited Vulnerability

CVE-2021-25370

Samsung · Mobile Devices

Samsung Mobile Devices Memory Corruption Vulnerability

Date added
BOD 22-01 due date
CWE CWE-416
Ransomware Unknown

CISA description

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.

Required action

Apply updates per vendor instructions.