CVE-2024-31957

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

History

12 Jul 2024, 14:53

Type Values Removed Values Added
Summary
  • (es) Se descubrió una vulnerabilidad en los procesadores móviles Samsung Exynos 2200 y Exynos 2400 donde carecen de una verificación para la validación de identificadores nativos, lo que puede resultar en un ataque DoS (denegación de servicio) al desasignar una longitud no válida.
First Time Samsung
Samsung exynos 2200 Firmware
Samsung exynos 2400 Firmware
Samsung exynos 2200
Samsung exynos 2400
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.5
CPE cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
CWE CWE-1284

09 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 18:15

Updated : 2024-07-12 14:53


NVD link : CVE-2024-31957

Mitre link : CVE-2024-31957

CVE.ORG link : CVE-2024-31957


JSON object : View

Products Affected

samsung

  • exynos_2400_firmware
  • exynos_2200
  • exynos_2400
  • exynos_2200_firmware
CWE
CWE-1284

Improper Validation of Specified Quantity in Input