Vulnerability record · CVE-2021-25371 · published 26 March 2021
CVE-2021-25371: Samsung Android DSP driver allows loading arbitrary ELF libraries
Samsung · Android
The DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the intended isolation of the DSP and lets code run in a privileged component. It matters because the DSP handles sensitive audio and sensor processing, so tampering there can compromise confidentiality and integrity.
Description
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is listed in CISA KEV as exploited, though the local high-privilege vector and low EPSS temper the immediate risk.
What it is
The DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the intended isolation of the DSP and lets code run in a privileged component. It matters because the DSP handles sensitive audio and sensor processing, so tampering there can compromise confidentiality and integrity.
Impact
An attacker who can reach the driver gains the ability to execute arbitrary code within the DSP, affecting confidentiality, integrity and availability of data processed there. The CVSS vector indicates high impact across all three categories.
Attack surface
The vector is local (AV:L) with high privileges required (PR:H) and no user interaction (UI:N), so the flaw is reached by a locally positioned, already privileged actor rather than remotely. No authentication over a network is involved.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-06-29, indicating known exploitation, while EPSS is low at 0.00802 (54.8th percentile). References are vendor advisories and the CISA KEV entry only.
What to do
- Apply the Samsung SMR Mar-2021 Release 1 or later security update to affected devices.
- If updates are unavailable, discontinue use of the affected product per CISA guidance.
- Restrict local privileged access and debug interfaces on managed devices.
- Track device fleet patch levels to confirm the March 2021 SMR baseline is met.
Detection
- Monitor for unexpected ELF library loads into DSP-related processes on Samsung devices.
- Alert on anomalous DSP driver access from non-system or debug contexts.
- Audit devices for missing SMR Mar-2021 or later patch level.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25371 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Unspecified Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25371 | US Government Resource |
Track CVE-2021-25371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.