← Vulnerability feed

Vulnerability record · CVE-2023-21492 · published 4 May 2023

CVE-2023-21492: Samsung Android kernel pointer logging enables ASLR bypass

Samsung · Android

Samsung Android devices log kernel pointers to a log file before the SMR May-2023 Release 1 fix. A privileged local attacker who can read those logs learns kernel memory layout, defeating ASLR. The flaw is an information leak, not code execution, but it weakens a core exploit mitigation.

4.4 CVSS 3.1 Medium CISA KEV since 19 May 2023 EPSS 2.6% · top 15.6% CWE-532 · Sensitive information in log file
4.4CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

medium priorityIt is a local, high-privilege information leak with known exploitation per KEV, but it requires an existing privileged foothold and only enables ASLR bypass rather than direct compromise.

What it is

Samsung Android devices log kernel pointers to a log file before the SMR May-2023 Release 1 fix. A privileged local attacker who can read those logs learns kernel memory layout, defeating ASLR. The flaw is an information leak, not code execution, but it weakens a core exploit mitigation.

Impact

An attacker with local privileged access gains kernel address information that can be used to bypass ASLR and improve the reliability of a follow-on kernel exploit. There is no direct confidentiality, integrity or availability loss beyond the leaked addresses.

Attack surface

Reached locally on the device; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N). The attacker must already have a privileged local foothold and the ability to read the affected log file.

Exploitation

CISA added it to KEV on 2023-05-19 with a 2023-06-09 remediation due date, indicating known exploitation, while EPSS is low at 0.02554 (84th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Samsung SMR May-2023 Release 1 (or later) security update per vendor instructions.
  • Restrict read access to device log files and log buffers to the minimum set of privileged processes.
  • Disable or reduce verbose kernel logging on production devices where policy allows.
  • Monitor for and investigate any local privileged process reading kernel log files.
  • Track KEV remediation deadlines and verify patch status across the Samsung Android fleet.

Detection

  • Alert on privileged processes reading kernel log files or log buffers outside expected system components.
  • Audit device logs for kernel pointer values (0xffff... style addresses) appearing in log output.
  • Monitor for post-exploitation behavior that follows an ASLR bypass, such as kernel exploit attempts.
  • Verify patch level on managed Samsung Android devices against the May-2023 SMR baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-21492 to the Known Exploited Vulnerabilities catalog on 19 May 2023 as "Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 June 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21492 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-21042Samsung Android libimagecodec.quram.so out-of-bounds writeAn out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execu…KEVEPSS 33%analysed9.8CVE-2025-21043Samsung Android libimagecodec Out-of-Bounds Write RCEAn out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable witho…KEVEPSS 2.1%analysed7.8CVE-2021-25487Samsung Android modem driver buffer bounds flaw enables code executionThe modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can derefere…KEVEPSS 0.64%analysed7.1CVE-2021-25337Samsung clipboard service access control flaw exposes local filesSamsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or wr…KEVEPSS 2.8%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed6.7CVE-2021-25372Samsung Android DSP driver improper boundary check allows out-of-bounds memory accessThe Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Rel…KEVEPSS 0.80%analysed6.4CVE-2021-25395Samsung Android MFC charger driver race condition bypasses signature checkA race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters…KEVEPSS 0.37%analysed6.4CVE-2021-25394Samsung Android MFC charger driver use-after-free via race conditionThe MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but…KEVEPSS 0.40%analysed

Source: NIST National Vulnerability Database (record CVE-2023-21492), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.