5.7
CVE-2024-53922
- EPSS 0.16%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 28.09.2026 14:10:00
- Erkennungen
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSamsung
≫
Produkt
Exynos 8890 firmware
Default Statusunaffected
Version
V7
Status
affected
Version
V9
Status
affected
Version
V920
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 5.7 | 1.4 | 4.2 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-1284 Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
https://semiconductor.samsung.com/support/quality-support/product-security-updates/
https://diconium.com/de/blog/cybersecurity/hunting-bugs-in-linux-kernel-with-kasan
https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-53922/