A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.
References
Configurations
History
26 Jun 2025, 20:46
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* |
|
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory | |
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27386/ - Vendor Advisory | |
First Time |
Samsung exynos 1380
Samsung Samsung exynos 1380 Firmware Samsung exynos 1480 Firmware Samsung exynos 1480 |
21 Nov 2024, 09:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - | |
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27386/ - |
01 Aug 2024, 13:48
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
11 Jul 2024, 13:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 21:15
Updated : 2025-06-26 20:46
NVD link : CVE-2024-27386
Mitre link : CVE-2024-27386
CVE.ORG link : CVE-2024-27386
JSON object : View
Products Affected
samsung
- exynos_1480_firmware
- exynos_1480
- exynos_1380_firmware
- exynos_1380
CWE
CWE-20
Improper Input Validation