Impact
A double‑free vulnerability in the Exynos Multi‑Media Framework (MFC) encoder driver arises from improper cleanup of dma_buf references during error handling. This flaw allows kernel memory corruption and may enable an attacker to execute arbitrary code with kernel privileges, classified as CWE‑415.
Affected Systems
Samsung devices that run Exynos firmware versions 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, as well as wearable models W920, W930, and W1000, are affected. Firmware containing the vulnerable MFC driver is impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can potentially trigger the flaw via the MFC encoder interface from user space, requiring the ability to cause an encoding error, thereby creating a local privilege escalation path to kernel code execution.
OpenCVE Enrichment