Impact
An out‑of‑bounds write occurs when a malformed message is sent to the test_msg sysfs interface in Samsung Exynos camera firmware. The flaw arises from improper bounds checking (CWE‑787) and can corrupt kernel memory, causing a crash that forces the device to reboot or become unresponsive. The primary consequence is a denial of service; there is no evidence that confidentiality or integrity is directly compromised. Because the exploit is confined to the camera subsystem, it does not provide a straightforward path to arbitrary code execution.
Affected Systems
Samsung Exynos processors 1330, 1380, 1480, 2400, 1580, and 2500 are affected. Firmware versions that expose the test risk. Exact firmware version ranges are not disclosed, so all current releases containing the vulnerable interface should be reviewed.
Risk and Exploitability
The CVSS score of 2.8 indicates low overall severity, and the EPSS score is below 1%, showing a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of widespread active exploitation. The likely attack vector is a local privileged user who can write to the sysfs entry; if the interface is exposed to unprivileged users or applications, remote exploitation becomes possible. Triggering the flaw requires writing a malicious payload to /sys/.../test_msg, which does not involve network activity, limiting remote exploitation potential.
OpenCVE Enrichment