Impact
A double‑free bug in the MFC encoder driver of Samsung Exynos 850 firmware can corrupt kernel memory. If successfully triggered, the flaw permits an attacker to run arbitrary code with kernel privileges, a vulnerability classified as CWE‑415.
Affected Systems
Samsung devices that run the Exynos 850 firmware are affected. The flaw exists within the driver shipped with that firmware and therefore all hardware platforms using that firmware are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% shows a very low likelihood of exploitation at present. Based on the description, it is inferred that the flaw can be triggered from user‑space code that causes an encoding error, creating a local privilege escalation path to kernel code execution. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment