← לוח פגיעויות

CVE-2021-25487

גבוהה 7.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Samsung Mobile Devices Out-of-Bounds Read Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

תיאור (מקור, אנגלית)

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-25/7/2026
CWE
CWE-125

מוצרים מושפעים

samsung: android

קישורים