Vulnerability record · CVE-2021-25372 · published 26 March 2021
CVE-2021-25372: Samsung Android DSP driver improper boundary check allows out-of-bounds memory access
Samsung · Android
The Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Release 1, so unpatched Samsung devices remain exposed. Because the DSP driver handles media processing, memory corruption there can be reached through crafted input rather than only through a local app.
Description
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with confirmed exploitation, but the local high-privilege vector and low EPSS score limit broad opportunistic risk.
What it is
The Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Release 1, so unpatched Samsung devices remain exposed. Because the DSP driver handles media processing, memory corruption there can be reached through crafted input rather than only through a local app.
Impact
An attacker who can trigger the boundary check failure gains out-of-bounds read/write in the DSP driver, which can corrupt memory and potentially lead to code execution in the driver context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is local (AV:L) with high privileges required (PR:H) and no user interaction (UI:N), so exploitation requires an attacker to already have a privileged local position on the device. The description does not specify the exact entry point into the DSP driver.
Exploitation
CVE-2021-25372 is listed in CISA KEV with a due date of 2023-07-20, indicating known exploitation in the wild, though the EPSS 30-day probability is low at roughly 0.8 percent. No ransomware campaign use is documented.
What to do
- Apply the Samsung SMR Mar-2021 Release 1 or later security update to affected devices.
- If updates are unavailable, discontinue use of the affected device per CISA guidance.
- Restrict local privileged access and review which apps or services can reach the DSP driver.
- Track device patch levels and enforce minimum security patch versions in MDM policy.
Detection
- Monitor for crashes or abnormal restarts tied to DSP or media driver components.
- Alert on unexpected privileged local processes interacting with DSP driver interfaces.
- Correlate device patch level against SMR Mar-2021 Release 1 to find unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25372 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Improper Boundary Check Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25372 | US Government Resource |
Track CVE-2021-25372 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25372), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.