← Vulnerability feed

Vulnerability record · CVE-2021-25372 · published 26 March 2021

CVE-2021-25372: Samsung Android DSP driver improper boundary check allows out-of-bounds memory access

Samsung · Android

The Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Release 1, so unpatched Samsung devices remain exposed. Because the DSP driver handles media processing, memory corruption there can be reached through crafted input rather than only through a local app.

6.7 CVSS 3.1 Medium CISA KEV since 29 Jun 2023 EPSS 0.80% · top 45.0% CWE-787 · Out-of-bounds writeCWE-703 · CWE-703
6.7CVSS 3.1 base score, v2 7.2
0.80%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with confirmed exploitation, but the local high-privilege vector and low EPSS score limit broad opportunistic risk.

What it is

The Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Release 1, so unpatched Samsung devices remain exposed. Because the DSP driver handles media processing, memory corruption there can be reached through crafted input rather than only through a local app.

Impact

An attacker who can trigger the boundary check failure gains out-of-bounds read/write in the DSP driver, which can corrupt memory and potentially lead to code execution in the driver context. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The CVSS vector is local (AV:L) with high privileges required (PR:H) and no user interaction (UI:N), so exploitation requires an attacker to already have a privileged local position on the device. The description does not specify the exact entry point into the DSP driver.

Exploitation

CVE-2021-25372 is listed in CISA KEV with a due date of 2023-07-20, indicating known exploitation in the wild, though the EPSS 30-day probability is low at roughly 0.8 percent. No ransomware campaign use is documented.

What to do

  • Apply the Samsung SMR Mar-2021 Release 1 or later security update to affected devices.
  • If updates are unavailable, discontinue use of the affected device per CISA guidance.
  • Restrict local privileged access and review which apps or services can reach the DSP driver.
  • Track device patch levels and enforce minimum security patch versions in MDM policy.

Detection

  • Monitor for crashes or abnormal restarts tied to DSP or media driver components.
  • Alert on unexpected privileged local processes interacting with DSP driver interfaces.
  • Correlate device patch level against SMR Mar-2021 Release 1 to find unpatched endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-25372 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Improper Boundary Check Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-21042Samsung Android libimagecodec.quram.so out-of-bounds writeAn out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execu…KEVEPSS 33%analysed9.8CVE-2025-21043Samsung Android libimagecodec Out-of-Bounds Write RCEAn out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable witho…KEVEPSS 2.1%analysed7.8CVE-2021-25487Samsung Android modem driver buffer bounds flaw enables code executionThe modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can derefere…KEVEPSS 0.64%analysed7.1CVE-2021-25337Samsung clipboard service access control flaw exposes local filesSamsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or wr…KEVEPSS 2.8%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed6.4CVE-2021-25395Samsung Android MFC charger driver race condition bypasses signature checkA race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters…KEVEPSS 0.37%analysed6.4CVE-2021-25394Samsung Android MFC charger driver use-after-free via race conditionThe MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but…KEVEPSS 0.40%analysed5.5CVE-2021-25489Samsung Android modem driver format string bug causes kernel panicSamsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA…KEVEPSS 0.53%analysed

Source: NIST National Vulnerability Database (record CVE-2021-25372), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.