CVE-2021-25370 is a memory corruption vulnerability in the dpu driver of Samsung Android devices, stemming from an incorrect file descriptor implementation. This flaw can lead to a kernel panic, resulting in a denial of service. With a CVSS score of 4.4 (Medium), it requires high privileges for local exploitation and has a high impact on availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and media coverage highlighting its use by spyware vendors, despite a lack of public exploit code in common repositories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:8.0:-:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:samsung:android:8.1:-:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:9.0:smr-apr-2019-r1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:9.0:smr-apr-2020-r1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:9.0:smr-aug-2019-r1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.