LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-25370 to its Known Exploited Vulnerabilities catalog on Nov 8, 2022, with a federal patch deadline of Nov 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic…

CVE-2021-25370 is a memory corruption vulnerability in Samsung mobile devices that use the Mali GPU. An incorrect implementation for handling a file descriptor in the dpu driver can cause memory corruption that leads to a kernel panic. The issue was chained with CVE-2021-25337 and CVE-2021-25369. For enterprise and security teams managing fleets of Samsung devices, this matters because kernel-level instability or compromise on mobile endpoints can disrupt operations, enable further privilege escalation chains, and increase the risk of device takeover if left unpatched. Confirm all product and version details against the vendor advisory.

How it works

The weakness is classified as CWE-416. According to the available summary, Samsung mobile devices using the Mali GPU contain an incorrect implementation for handling a file descriptor inside the dpu driver. That flaw produces memory corruption and can result in a kernel panic. Public detail on exact exploit mechanics is limited; an attacker who can reach the vulnerable driver path would abuse the incorrect file-descriptor handling to trigger the corruption. The vulnerability has been observed chained with CVE-2021-25337 and CVE-2021-25369, which can increase impact by combining multiple flaws. Specifics of any local or remote trigger conditions must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

This issue affects Samsung mobile devices that incorporate the Mali GPU and the associated dpu driver. Such devices commonly appear as employee smartphones, tablets, or managed mobile endpoints in corporate environments. Inventory steps include:

Telemetry signs of exploitation are not detailed in public sources for this CVE; monitor for unexpected kernel panics, repeated device reboots, or anomalous local privilege activity that might indicate chaining with the related CVEs. Always validate affected configurations against the official vendor advisory.

How to remediate

Apply the updates supplied by Samsung according to the vendor instructions, as required by the CISA guidance for this vulnerability. Prioritize devices that are in active use and those that have not yet received the security patch addressing the dpu-driver file-descriptor handling flaw. After patching:

Document the remediation status in your asset inventory so that residual risk can be tracked.

If you can't patch immediately

When immediate patching is not feasible, reduce exposure with compensating controls while the vendor update is scheduled:

These steps lower risk but do not eliminate the underlying memory-corruption condition; plan to apply the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure even when ransomware use is not documented for this specific CVE. If you suspect devices were targeted, treat them as potentially compromised: isolate them, collect forensic images where feasible, rotate credentials that may have been accessible from the device, and review access logs for lateral movement. Readers can also run a free exposure scan of their email addresses against known breach data sets to determine whether associated accounts appear in public breach corpora, then follow standard credential-reset and monitoring practices.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · Mobile Devices
WeaknessCWE-416
Added to CISA KEVNov 8, 2022
Federal patch deadlineNov 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities