November 8, 2022 · Applied Cybernetics Group
CVE-2021-25370 — Samsung Mobile Devices
Samsung Mobile Devices Memory Corruption Vulnerability
- Added to KEV
2022-11-08- Federal due date
2022-11-29- Vendor
- Samsung
- Product
- Mobile Devices
- EPSS
- 66.0th percentile (score 0.005, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-25370
CISA short description
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.
Required action
Apply updates per vendor instructions.