Impact
An untrusted pointer dereference in the camera driver of Samsung Exynos 1580 firmware is triggered when a malformed message is received. The flaw allows memory that should not be accessible to be read, exposing limited internal data, and can cause the driver to crash, resulting in a denial of service. This weakness is listed as CWE-822, the improper handling of a pointer that could lead to corruption or reading of uninitialized memory.
Affected Systems
The vulnerability affects Samsung Exynos 1580 firmware; Samsung also notes the flaw exists in Exynos 2500. Devices that rely on the camera driver within these SoCs are impacted. Firmware updates for these processors are available from Samsung’s semiconductor support site.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no widespread exploitation deliver a crafted message to the camera driver, which typically requires local access or the ability to run privileged code on the device. Consequently, the risk is primarily to devices with compromised applications rather than through remote network exploitation.
OpenCVE Enrichment