Impact
A malformed ioctl command sent to the Wi‑Fi interface device causes an improper buffer allocation, leading to an out‑of‑bounds write. This flaw can crash the Wi‑Fi driver, rendering the wireless functionality unavailable and resulting in a denial of service. The vulnerability is recognized as a classic out‑of‑bounds write, classified as CWE‑787.
Affected Systems
The vulnerability affects the Samsung Exynos 1330 firmware bundle. In other families such as Exynos 1380, 1480, 1580, 1680, W920, W930, and W1000, but the published remediation specifically addresses the Exynos 1330 firmware. No firmware revision range is disclosed, so all current releases of the Exynos 1330 firmware should be considered vulnerable.
Risk and Exploitability
The CVSS score of 2.8 indicates a low severity rating, and the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to issue a crafted ioctl to the Wi‑Fi driver, which typically requires local or privileged access. Remote exploitation is unlikely, but a local user with sufficient privileges could trigger the crash and disrupt device operation.
OpenCVE Enrichment