Impact
A stack-based buffer overflow exists in the camera driver of Samsung Exynos processors. When a driver writes past the bounds of an array on the stack, corrupting control data and causing the camera component to crash. The resulting loss of camera functionality constitutes a denial of service for the device. This weakness is a classic buffer overflow (CWE-121).
Affected Systems
The flaw affects Samsung Exynos firmware on the Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680 processor families. All devices running these firmware versions are vulnerable if the camera driver receives a malformed request.
Risk and Exploitability
The CVSS score of 7.5 categorizes the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed that no publicly known exploits exist. The defect is local in scope; attackers would need to deliver a crafted message to the camera driver, likely through a malicious application granted camera access or via local privileged code. Successful exploitation would lead to a local denial of service, disabling camera functionality but not compromising other system components or enabling remote code execution.
OpenCVE Enrichment