Impact
A use‑after‑free flaw exists in the DRM HDR driver of Samsung Exynos mobile processors. The bug is triggered when the driver fails to clean up properly during a virtual memory mapping (vmap) error, causing the kernel to crash. The resulting kernel panic disrupts availability and can terminate all services running on the affected device. This weakness is classified as CWE‑416 and does not provide an attacker with direct privilege escalation or data exposure.
Affected Systems
The advisory specifically lists Samsung Exynos 1280 firmware, but the vendor’s description states the defect also impacts other Exynos models such as 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. All affected systems run the corresponding DPU firmware with the DRM HDR driver.
Risk and Exploitability
The CVSS base score of 4.2 indicates a moderate severity. The EPSS score of < 1% demonstrates a very low likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog, so no known active exploits have been reported. Since the vulnerability causes a kernel panic rather than code execution, the likely attack vector is local or privileged input that triggers a vmap failure in the DRM HDR driver. The lack of a remote trigger and the absence of known exploits suggest a moderate, yet still significant risk for systems that have not applied a timely firmware update.
OpenCVE Enrichment