Impact
A malformed Netlink command can trigger an out‑of‑bounds read in the Wi‑Fi driver of Samsung Exynos processors, potentially allowing an attacker to read sensitive memory contents. The weakness is an improper read of memory beyond an array bounds (CWE‑125), which can expose confidential data without modifying system state.
Affected Systems
This vulnerability affects Samsung’s Exynos 850, 1280, 1330, 1380, 1480, 2400 firmware, as well as the W920 details are provided, so all current releases of these devices are potentially impacted until a patch is published.
Risk and Exploitability
The CVSS score of 2.8 indicates low severity, and KEV is not listed. The EPSS score of < 1% indicates a very low exploitation probability. The likely attack vector is inferred to require an attacker who can send crafted Netlink messages to the Wi‑Fi driver, which may necessitate local or privileged access to the device. While no public exploits are known, the potential for information leakage warrants monitoring of local Wi‑Fi activity.
OpenCVE Enrichment