CVE-2024-31957

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

History

12 Jul 2024, 14:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.5
First Time Samsung
Samsung exynos 2400
Samsung exynos 2400 Firmware
Samsung exynos 2200
Samsung exynos 2200 Firmware
CWE CWE-1284
Summary
  • (es) Se descubrió una vulnerabilidad en los procesadores móviles Samsung Exynos 2200 y Exynos 2400 donde carecen de una verificación para la validación de identificadores nativos, lo que puede resultar en un ataque DoS (denegación de servicio) al desasignar una longitud no válida.
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory
CPE cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

09 Jul 2024, 18:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 18:15

Updated : 2024-07-12 14:53


NVD link : CVE-2024-31957

Mitre link : CVE-2024-31957

CVE.ORG link : CVE-2024-31957


JSON object : View

Products Affected

samsung

  • exynos_2400
  • exynos_2200
  • exynos_2400_firmware
  • exynos_2200_firmware
CWE
CWE-1284

Improper Validation of Specified Quantity in Input