Impact
An improper synchronization of a global variable in Samsung’s Exynos Wi‑Fi driver creates a use‑after‑free condition. When an attacker invokes the driver’s ioctl function concurrently from multiple threads, a race condition can be triggered, freeing an object that may still be in use.
Affected Systems
The vulnerability affects Samsung Exynos mobile and wearable processors, specifically the 850, 980, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000 families and their associated firmware. No specific firmware version ranges are listed, so any device using these chips with the unpatched driver could be impacted.
Risk and Exploitability
With a CVSS score of 7.0, the flaw is considered moderate severity, and the EPSS score indicates a less than 1 percent chance of exploitation in the wild. The vulnerability is not yet in the CISA KEV catalog. Exploitation requires the ability to send race‑condition inducing ioctl calls to the driver, suggesting a local or device‑based attack surface rather than a network‑exposed vector.
OpenCVE Enrichment