CVE-2019-19273

On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
OR cpe:2.3:h:samsung:galaxy_note8:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s8:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s8_plus:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:h:samsung:exynos_8895:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () https://census-labs.com/news/2020/10/08/samsung-hypervisor-rkp-arbitrary-zero-write/ - Exploit, Third Party Advisory () https://census-labs.com/news/2020/10/08/samsung-hypervisor-rkp-arbitrary-zero-write/ - Exploit, Third Party Advisory
References () https://security.samsungmobile.com/securityUpdate.smsb - Vendor Advisory () https://security.samsungmobile.com/securityUpdate.smsb - Vendor Advisory

Information

Published : 2020-02-04 16:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19273

Mitre link : CVE-2019-19273

CVE.ORG link : CVE-2019-19273


JSON object : View

Products Affected

samsung

  • galaxy_s8
  • exynos_8895
  • galaxy_note8
  • galaxy_s8_plus

google

  • android
CWE
CWE-787

Out-of-bounds Write