Impact
An out-of-bounds read and write occurs in the CustOS driver when a process requests an oversized shared memory region from the custos_iwc device. The resulting memory corruption or information leakage can affect the integrity and confidentiality of data stored in the same address space, potentially destabilizing the device. Based on the description, it is inferred that the vulnerability arises from insufficient bounds checking when allocating shared memory, allowing a crafted request size to overflow internal buffers.
Affected Systems
The vulnerability applies to Samsung mobile processors running Exynos 1580 firmware that incorporate the CustOS driver. No specific firmware versions are listed as affected, so all device configurations using Exynos 1580 firmware that ship the CustOS driver are potentially impacted.
Risk and Exploitability
The CVSS score of 4.2 places the vulnerability in the moderate range, and the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild. The CVE is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the ability to send a crafted request to the user‑ or process‑level privileges with access to the device node; a more privileged attacker might trigger kernel‑level effects. No public exploitation is reported, but the flaw could be abused by any process that can supply a crafted request size to the driver.
OpenCVE Enrichment