Impact
An improper loop termination condition in Samsung’s Shannon SM Task allows a malformed SM message to cause a required service to become unresponsive. This flaw is a classic infinite-loop issue (CWE‑835) that results in a denial of service, as the affected service cannot complete its operation, potentially leading to system instability or blocking other functions.
Affected Systems
The CVE specifically references Samsung’s Exynos 850 firmware, but the description lists the same flaw in numerous Samsung Exynos models, including 9810, 9610, 9820, 980, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, as well as Exynos Modems 5123 and 5300 and the Auto T5123. Devices that run any of these firmware images and rely on the Shannon SM Task are impacted.
Risk and Exploitability
The CVSS v3.1 score of 2.8 places the flaw in the low‑severity band, and the EPSS score of 0.00091 indicates a very low likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a malformed SM message to the processor, a capability that is normally restricted to privileged or local code. Therefore, the attack surface is primarily the internal interface that accepts SM messages, and real‑world exploitation would likely require local code execution or compromised firmware.
OpenCVE Enrichment