CVE-2024-31957

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.2

12 Jul 2024, 14:53

Type Values Removed Values Added
First Time Samsung
Samsung exynos 2200 Firmware
Samsung exynos 2400 Firmware
Samsung exynos 2200
Samsung exynos 2400
Summary
  • (es) Se descubrió una vulnerabilidad en los procesadores móviles Samsung Exynos 2200 y Exynos 2400 donde carecen de una verificación para la validación de identificadores nativos, lo que puede resultar en un ataque DoS (denegación de servicio) al desasignar una longitud no válida.
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.5
CPE cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
CWE CWE-1284

09 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 18:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-31957

Mitre link : CVE-2024-31957

CVE.ORG link : CVE-2024-31957


JSON object : View

Products Affected

samsung

  • exynos_2400_firmware
  • exynos_2200_firmware
  • exynos_2200
  • exynos_2400
CWE
CWE-1284

Improper Validation of Specified Quantity in Input