← Back to browse · API

CVE-2021-25487

Severity
HIGH
CVSS
7.3
EPSS
0.00635
Risk score
54.42
CISA KEV
Yes
PoC
No
Published
2023-06-29
Modified
2023-06-29
First seen
2026-08-07
Aliases
EUVD-2021-12383, GHSA-4FPW-J345-Q48R
Products
Samsung Mobile:Samsung Mobile Devices O(8.1), P(9.0), Q(10.0), R(11.0) <SMR Oct-2021 Release 1, Samsung:Mobile Devices
Sources
euvd EUVD-2021-12383
cisa.gov CVE-2021-25487

Description

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

References