CVE-2024-27386: Samsung Exynos 1380 Firmware
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.
Affected products
- Samsung Exynos 1380 Firmware: affected versions not specified
- Samsung Exynos 1480 Firmware: affected versions not specified
Published 2024-07-09. Last modified 2026-06-17.