Skip to content

Product Security Update

Product Security Update

    • Use After Free vulnerability in the GPU instance may lead to Local Privilege Escalation (LPE)

      CVE ID CVE-2023-42482
      Title Use After Free in Samsung GPU
      Affected Product Mobile Processor
      Affected Version Exynos 2200
      Severity High (7.8)
      Reported Date 2023. 6. 13
      Patched Version ※ Not affect all vendor's product, please contact your vendor.
      Acknowledgment APVI/Google (Xingyu Jin)
    • Double Free vulnerability in the GPU instance may lead to Local Privilege Escalation (LPE)

      CVE ID CVE-2023-41911
      Title Double Free in Samsung GPU
      Affected Product Mobile Processor
      Affected Version Exynos 2200
      Severity High (7.8)
      Reported Date 2023. 6. 13
      Patched Version ※ Not affect all vendor's product, please contact your vendor.
      Acknowledgment APVI/Google (Xingyu Jin)
    • A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

      CVE ID CVE-2023-41929
      Title DLL hijacking vulnerability
      Affected Product Samsung Memory Card & UFD Authentication Utility PC Software
      Affected Version Below 1.0.1 version
      Severity 7.3 (High)
      Reported Date 2023. 6. 29
      Patched Version 1.0.2
    • Missing validation of null pointer can cause abnormal termination.

      CVE ID CVE-2023-37368
      Title An invalid pointer dereference in mobility management processing of Shannon BaseBand
      Affected Product Exynos Mobile Processor, Automotive Processor, and Modem
      Affected Chipset Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, Exynos Auto T5123
      Severity 5.9 (Medium)
      Reported Date 2023. 4. 28
      Patched Version ※ Not affect all vendor’s product, please contact your vendor.
    • Improperly implemented security check for standard can disallow desired services for a while.

      CVE ID CVE-2023-37367
      Title Improper authorization of 5G NAS messages
      Affected Product Exynos Mobile Processor, Automotive Processor, and Modem
      Affected Chipset Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, Exynos Auto T5123
      Severity 5.3 (Medium)
      Reported Date 2023. 4. 28
      Patched Version ※ Not affect all vendor’s product, please contact your vendor.
    • Interger overflow at buffer indext can prevent the execution of requested services via a crafted application.

      CVE ID CVE-2023-40353
      Title OOB-Read in DSP Kernel Driver
      Affected Product Exynos Mobile Processor
      Affected Chipset Exynos 980, Exynos 2100
      Severity Low (2.0)
      Reported Date 2023. 5. 10
      Patched Version ※ Not affect all vendor’s product, please contact your vendor.
    • Improper handling of length parameter inconsistency can cause incorrect packet filtering.

      CVE ID CVE-2023-37377
      Title OOB-Read in MBIM driver
      Affected Product Mobile Processor, Wearable Processor
      Affected Chipset Exynos 980, Exynos 850, Exynos 2100, Exynos W920, Exynos 1080
      Severity Low (2.0)
      Reported Date 2023. 5. 26
      Patched Version ※ Not affect all vendor’s product, please contact your vendor.