Vulnerability record · CVE-2021-25487 · published 6 October 2021
CVE-2021-25487: Samsung Android modem driver buffer bounds flaw enables code execution
Samsung · Android
The modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can dereference an invalid function pointer, which the vendor states leads to arbitrary code execution. It was fixed in the SMR Oct-2021 Release 1 update.
Description
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus CISA KEV listing outweighs the low EPSS score.
What it is
The modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can dereference an invalid function pointer, which the vendor states leads to arbitrary code execution. It was fixed in the SMR Oct-2021 Release 1 update.
Impact
An attacker who can reach the vulnerable code path gains arbitrary code execution in the modem interface driver context, with high impact to confidentiality, integrity and availability.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached from code already running on the device rather than over the network. No further detail on the exact entry point is given in the record.
Exploitation
CVE-2021-25487 is listed in CISA KEV (added 2023-06-29), indicating known exploitation, while EPSS is low at roughly 0.6% 30-day probability. No ransomware campaign use is recorded.
What to do
- Apply the Samsung SMR Oct-2021 Release 1 (or later) firmware update; this is the vendor fix for the flaw.
- If a device cannot be updated, discontinue use per CISA KEV guidance.
- Restrict installation and execution of untrusted local apps, since the vector requires local access with low privileges.
- Track Samsung monthly security maintenance releases for devices still in support and confirm the October 2021 patch level or newer.
Detection
- Inventory Samsung Android devices and verify build/patch level is SMR Oct-2021 Release 1 or later.
- Monitor for unexpected crashes or abnormal behavior in modem interface driver processes on affected devices.
- Watch for local privilege-escalation activity or suspicious apps invoking modem interface functionality outside normal telephony use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25487 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Out-of-Bounds Read Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25487 | US Government Resource |
Track CVE-2021-25487 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.