CVE-2024-31957

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.2
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory

12 Jul 2024, 14:53

Type Values Removed Values Added
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/ - Vendor Advisory
CPE cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
First Time Samsung exynos 2400 Firmware
Samsung exynos 2400
Samsung exynos 2200
Samsung exynos 2200 Firmware
Samsung
Summary
  • (es) Se descubrió una vulnerabilidad en los procesadores móviles Samsung Exynos 2200 y Exynos 2400 donde carecen de una verificación para la validación de identificadores nativos, lo que puede resultar en un ataque DoS (denegación de servicio) al desasignar una longitud no válida.
CWE CWE-1284
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.5

09 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 18:15

Updated : 2025-03-25 17:15


NVD link : CVE-2024-31957

Mitre link : CVE-2024-31957

CVE.ORG link : CVE-2024-31957


JSON object : View

Products Affected

samsung

  • exynos_2400_firmware
  • exynos_2400
  • exynos_2200
  • exynos_2200_firmware
CWE
CWE-1284

Improper Validation of Specified Quantity in Input