Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-27386


A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.


Published

2024-07-09T21:15:12.483

Last Modified

2025-06-26T20:46:25.353

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System samsung exynos_1380_firmware - Yes
Hardware samsung exynos_1380 - No
Operating System samsung exynos_1480_firmware - Yes
Hardware samsung exynos_1480 - No

References