An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.
References
| Link | Resource |
|---|---|
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/ | Vendor Advisory |
| https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-27374/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
History
07 Nov 2025, 13:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Samsung exynos 1380 Firmware
Samsung exynos 1080 Samsung exynos 9820 Firmware Samsung exynos 2400 Firmware Samsung exynos 1330 Samsung exynos 980 Firmware Samsung exynos 2400 Samsung exynos 1280 Firmware Samsung exynos 2200 Firmware Samsung exynos 2200 Samsung exynos 9825 Firmware Samsung exynos 1480 Samsung exynos 9820 Samsung exynos 9825 Samsung exynos 1480 Firmware Samsung Samsung exynos 1280 Samsung exynos 1330 Firmware Samsung exynos 980 Samsung exynos 1080 Firmware Samsung exynos 850 Samsung exynos 1380 Samsung exynos 850 Firmware |
|
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory | |
| References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-27374/ - Vendor Advisory | |
| CPE | cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1080_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_850:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_980_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_9825_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_9820_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_9825:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1330:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_9820:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_980:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1080:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_850_firmware:-:*:*:*:*:*:*:* |
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-787 |
04 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-04 21:15
Updated : 2025-11-07 13:00
NVD link : CVE-2025-27374
Mitre link : CVE-2025-27374
CVE.ORG link : CVE-2025-27374
JSON object : View
Products Affected
samsung
- exynos_1480
- exynos_1330
- exynos_1080_firmware
- exynos_850_firmware
- exynos_2200
- exynos_1380_firmware
- exynos_9820
- exynos_850
- exynos_1280
- exynos_9820_firmware
- exynos_2200_firmware
- exynos_980
- exynos_1280_firmware
- exynos_2400_firmware
- exynos_1380
- exynos_2400
- exynos_1330_firmware
- exynos_1480_firmware
- exynos_9825_firmware
- exynos_980_firmware
- exynos_1080
- exynos_9825
CWE
CWE-787
Out-of-bounds Write
