Skip to content

CVE-2026-33970

In the Exynos 5G baseband, a NULL Pointer Dereference (CWE-476) vulnerability occurs when processing a malformed RRC Reconfiguration message

This table summarizes key information about the CVE-2026-33970, including its identifier, title, affected products, versions, severity, reporting date, patched versions, and acknowledgement status.
Category Content
CVE ID CVE-2026-33970
Description In the Exynos 5G baseband, a NULL Pointer Dereference (CWE-476) vulnerability occurs when processing a malformed RRC Reconfiguration message
Affected Product Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, Modem 5410
Affected Component NR RRC, L2
Severity Medium
Reported Date 2025-12-24
Acknowledgment Kai Tu, Tianchang Yang, Xiaotian Zhou, Ali Ranjbar, Abdullah Al Ishtiaq, Tianwei Wu, Yilu Dong, Syed Rafiul Hussain — SyNSec Lab at Penn State