Description
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

An improper loop termination condition in Samsung’s Shannon SM Task allows a malformed SM message to cause a required service to become unresponsive. This flaw is a classic infinite-loop issue (CWE‑835) that results in a denial of service, as the affected service cannot complete its operation, potentially leading to system instability or blocking other functions.

Affected Systems

The CVE specifically references Samsung’s Exynos 850 firmware, but the description lists the same flaw in numerous Samsung Exynos models, including 9810, 9610, 9820, 980, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, as well as Exynos Modems 5123 and 5300 and the Auto T5123. Devices that run any of these firmware images and rely on the Shannon SM Task are impacted.

Risk and Exploitability

The CVSS v3.1 score of 2.8 places the flaw in the low‑severity band, and the EPSS score of 0.00091 indicates a very low likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a malformed SM message to the processor, a capability that is normally restricted to privileged or local code. Therefore, the attack surface is primarily the internal interface that accepts SM messages, and real‑world exploitation would likely require local code execution or compromised firmware.

Generated by OpenCVE AI on September 15, 2026 at 16:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Exynos firmware to the latest security‑patched version available from Samsung’s product‑security‑updates portal.
  • If an update is unavailable, disable or restrict the use of the Shannon SM Task or the affected service in the firmware configuration, if such a configuration option exists.
  • Implement a watchdog or monitoring mechanism that detects when the service becomes unresponsive and triggers a system reboot or safe‑mode recovery to mitigate the denial‑of‑service impact.

Generated by OpenCVE AI on September 15, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Infinite Loop in Samsung Exynos Shannon SM Task Causing Denial of Service

Mon, 14 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unreachable Loop in Samsung Exynos Firmware

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unreachable Loop in Samsung Exynos Firmware

Mon, 14 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.
First Time appeared Samsung
Samsung exynos 850 Firmware
Weaknesses CWE-835
CPEs cpe:2.3:a:samsung:exynos_850_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 850 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Samsung Exynos 850 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T14:33:14.679Z

Reserved: 2023-06-30T00:00:00.000Z

Link: CVE-2023-37366

cve-icon Vulnrichment

Updated: 2026-09-16T14:33:07.872Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T06:16:53.907

Modified: 2026-09-22T19:56:19.073

Link: CVE-2023-37366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')