Vulnerability record · CVE-2021-25370 · published 26 March 2021
CVE-2021-25370: Samsung Android dpu driver file descriptor use-after-free causes kernel panic
Samsung · Android
The dpu driver in Samsung Android mishandles file descriptors, resulting in a use-after-free and memory corruption that leads to a kernel panic. The flaw is local and requires high privileges, so it matters mainly as a denial-of-service or privilege-escalation primitive on affected devices.
Description
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is in CISA KEV indicating known exploitation, but it requires local high privileges and only causes kernel panic, limiting severity.
What it is
The dpu driver in Samsung Android mishandles file descriptors, resulting in a use-after-free and memory corruption that leads to a kernel panic. The flaw is local and requires high privileges, so it matters mainly as a denial-of-service or privilege-escalation primitive on affected devices.
Impact
An attacker with local high privileges can corrupt kernel memory and crash the device, causing a denial of service; the record does not establish code execution or data disclosure.
Attack surface
Reached locally through the dpu driver interface; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so an attacker must already have elevated access on the device.
Exploitation
CVE-2021-25370 is listed in CISA KEV with a 2022-11-08 addition date, indicating known exploitation, while EPSS is low at 0.0089 (57.6th percentile); no ransomware use is documented.
What to do
- Apply the Samsung SMR Mar-2021 Release 1 or later firmware update per vendor instructions.
- Restrict local high-privilege access and audit accounts or processes with such rights on affected devices.
- Monitor Samsung security bulletins for updated firmware and reapply patches as released.
- Where patching is delayed, limit exposure of affected devices to untrusted local users or apps.
Detection
- Monitor device logs for kernel panics or crashes originating from the dpu driver.
- Track anomalous file descriptor operations or use-after-free indicators in kernel telemetry on Samsung Android devices.
- Correlate local privilege escalation attempts with dpu driver activity on managed endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25370 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Samsung Mobile Devices Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25370 | US Government Resource |
Track CVE-2021-25370 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25370), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.