CVE Vulnerabilities

CVE-2021-25371

Hidden Functionality

Published: Mar 26, 2021 | Modified: Feb 14, 2025
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

Name Vendor Start Version End Version
Android Samsung 10.0-smr-feb-2021-r1 (including) 10.0-smr-feb-2021-r1 (including)
Android Samsung 10.0-smr-jan-2021-r1 (including) 10.0-smr-jan-2021-r1 (including)
Android Samsung 11.0-smr-feb-2021-r1 (including) 11.0-smr-feb-2021-r1 (including)
Android Samsung 11.0-smr-jan-2021-r1 (including) 11.0-smr-jan-2021-r1 (including)

Potential Mitigations

References