Description
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
Published: 2026-09-13
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The buffer queue driver in Samsung Automotive Processor Exynos Auto 8890 firmware lacks a proper length check, allowing a malformed input to trigger a kernel crash that results in a denial of service. The flaw is a direct consequence of improper buffer validation (CWE‑120). A crash in the kernel disables all affected vehicle functions that rely on the crashed component, potentially bringing vehicle systems to a halt.

Affected Systems

Samsung Exynos Auto 8890 firmware is affected. No specific firmware versions were provided; vehicle systems running this firmware may crash when the buffer queue driver processes crafted data.

Risk and Exploitability

The CVSS score of 5.7 places the vulnerability in the moderate severity range. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA, it is inferred that an attacker would need to deliver maliciously crafted data to the buffer queue driver, possibly via the vehicle’s internal communication interfaces such as CAN or Ethernet. The attack would likely be local or remote if the interfaces are accessible, and successful exploitation would immediately reboot the operating system.

Generated by OpenCVE AI on September 15, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Samsung firmware update that includes a patch for the buffer queue driver
  • If a patch is not yet available, restrict or isolate external traffic to the affected automotive interfaces until the fix is applied
  • Configure network segmentation or firewall rules to limit traffic to the buffer queue driver’s communication channels, reducing exposure to crafted data

Generated by OpenCVE AI on September 15, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title kernel: Kernel: Denial of Service in buffer queue driver
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1284
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Sun, 13 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:16:48.107Z

Reserved: 2024-11-25T00:00:00.000Z

Link: CVE-2024-53922

cve-icon Vulnrichment

Updated: 2026-09-14T18:16:42.647Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T00:16:55.880

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-53922

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T00:00:00Z

Links: CVE-2024-53922 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-1284

    Improper Validation of Specified Quantity in Input