Impact
A time‑race condition causes a heap overflow that crashes the kernel. The crash results in a denial of service but does not provide an attacker with code execution or data disclosure.
Affected Systems
The vulnerability affects Samsung CPU families Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600 firmware. All devices running the affected firmware version are at risk until the patch is applied.
Risk and Exploitability
The CVSS score of 2.8 indicates low severity, and the EPSS score of < 1% indicates a very low probability of exploitation. Because the fault requires access to the kernel through the DRM HDR driver, the likely attack vector is local privilege escalation or a compromised application with kernel interaction, not external remote exploitation. The vulnerability is not listed in the CISA KEV catalog, further supporting the low exploitation likelihood.
OpenCVE Enrichment