Impact
The buffer queue driver in Samsung Automotive Processor Exynos Auto 8890 firmware lacks a proper length check, allowing a malformed input to trigger a kernel crash that results in a denial of service. The flaw is a direct consequence of improper buffer validation (CWE‑120). A crash in the kernel disables all affected vehicle functions that rely on the crashed component, potentially bringing vehicle systems to a halt.
Affected Systems
Samsung Exynos Auto 8890 firmware is affected. No specific firmware versions were provided; vehicle systems running this firmware may crash when the buffer queue driver processes crafted data.
Risk and Exploitability
The CVSS score of 5.7 places the vulnerability in the moderate severity range. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA, it is inferred that an attacker would need to deliver maliciously crafted data to the buffer queue driver, possibly via the vehicle’s internal communication interfaces such as CAN or Ethernet. The attack would likely be local or remote if the interfaces are accessible, and successful exploitation would immediately reboot the operating system.
OpenCVE Enrichment