Impact
The flaw is a double‑free in the Samsung Exynos DPU driver caused by improper pointer handling during DMA buffer reallocations, which can corrupt kernel memory and potentially lead to a use‑after‑free scenario. An attacker that can trigger the reallocation path could overwrite critical kernel data structures, creating a window for privilege escalation or denial of service. The weakness is classified as CWE‑415 and is tied to kernel memory integrity.
Affected Systems
The vulnerability affects Samsung mobile processors that ship with Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600 firmware. All firmware releases containing the unpatched DPU driver are impacted. Devices running these chipsets with the current firmware are at risk.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity. The EPSS score is less than 1% (0.00091), suggesting a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, implying no known widespread exploitation yet. The likely attack vector involves an attacker capable of interacting with the DMA engine, such as a privileged local process or a component driving the DPU, to trigger the double‑free. Because it requires kernel interaction, exploitation is constrained to local or privileged contexts, but the kernel memory corruption could provide a foothold for further privilege escalation.
OpenCVE Enrichment