← Vulnerability feed

Vulnerability record · CVE-2021-25369 · published 26 March 2021

CVE-2021-25369: Samsung Android sec_log improper access control leaks kernel data

Samsung · Android

Samsung Android devices contain an improper access control flaw in the sec_log file that exposes sensitive kernel information to userspace. The issue was fixed in the SMR MAR-2021 Release 1 maintenance release. Because kernel memory contents can reveal addresses and internal state, the leak matters for weakening later exploitation steps.

5.5 CVSS 3.1 Medium CISA KEV since 8 Nov 2022 EPSS 1.1% · top 35.2% CWE-200 · Information exposure
5.5CVSS 3.1 base score, v2 2.1
1.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe flaw is a local information leak rated CVSS 5.5, but its presence in CISA KEV signals real-world exploitation, raising it above a routine medium.

What it is

Samsung Android devices contain an improper access control flaw in the sec_log file that exposes sensitive kernel information to userspace. The issue was fixed in the SMR MAR-2021 Release 1 maintenance release. Because kernel memory contents can reveal addresses and internal state, the leak matters for weakening later exploitation steps.

Impact

A local attacker gains read access to sensitive kernel information, which can aid in defeating kernel protections and building further exploits. The flaw itself provides information disclosure, not code execution or privilege escalation.

Attack surface

The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so an attacker needs code already running on the device under a normal user context. No network or remote vector is described.

Exploitation

CVE-2021-25369 is listed in CISA KEV with a due date of 2022-11-29, indicating known exploitation, though the EPSS 30-day probability is low at roughly 1.1 percent. No ransomware campaign use is recorded.

What to do

  • Apply the Samsung SMR MAR-2021 Release 1 or later security maintenance release to affected devices.
  • Enforce timely Android security patch levels across managed Samsung fleets and block devices below the fixed SMR.
  • Restrict installation of untrusted apps and limit local code execution paths on sensitive devices.
  • Monitor vendor advisories for any follow-up fixes or revised patch guidance.

Detection

  • Track device patch level and flag Samsung Android devices below SMR MAR-2021 Release 1.
  • Monitor for suspicious local processes or apps attempting to read kernel log or sec_log interfaces.
  • Correlate endpoint telemetry for information-disclosure behavior preceding privilege escalation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-25369 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Samsung Mobile Devices Improper Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 November 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25369 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-21042Samsung Android libimagecodec.quram.so out-of-bounds writeAn out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execu…KEVEPSS 33%analysed9.8CVE-2025-21043Samsung Android libimagecodec Out-of-Bounds Write RCEAn out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable witho…KEVEPSS 2.1%analysed7.8CVE-2021-25487Samsung Android modem driver buffer bounds flaw enables code executionThe modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can derefere…KEVEPSS 0.64%analysed7.1CVE-2021-25337Samsung clipboard service access control flaw exposes local filesSamsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or wr…KEVEPSS 2.8%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed6.7CVE-2021-25372Samsung Android DSP driver improper boundary check allows out-of-bounds memory accessThe Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Rel…KEVEPSS 0.80%analysed6.4CVE-2021-25395Samsung Android MFC charger driver race condition bypasses signature checkA race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters…KEVEPSS 0.37%analysed6.4CVE-2021-25394Samsung Android MFC charger driver use-after-free via race conditionThe MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but…KEVEPSS 0.40%analysed

Source: NIST National Vulnerability Database (record CVE-2021-25369), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.