Impact
An out-of-bounds memory access vulnerability exists in the camera GDC driver of Samsung Exynos 1330, 1380, 1480, and 2400 processors. This flaw can corrupt kernel memory under certain conditions, which may enable privilege escalation or system instability.
Affected Systems
Samsung’s Exynos 1330, 1380, 1480, and 2400 mobile processors, with the firmware that includes the camera GDC driver, are affected. No specific firmware version ranges are disclosed.
Risk and Exploitability
The CVSS score of 3.5 indicates a low‑to‑moderate risk. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local attacker who can influence camera input or invoke camera functionality, as the flaw originates in the GDC driver. Exploitation would require conditions that trigger the out‑of‑bounds access, leading to kernel memory corruption. Overall, the probability of exploitation remains low given the low EPSS, but the potential impact could be substantial if the flaw is used for privilege escalation.
OpenCVE Enrichment