(CVE-2025-23107) Samsung Exynos NPU Driver Out-of-Bounds Write via Undersized User Buffer
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。我先看看文章内容。这篇文章是关于三星Galaxy S24+手机中的一个安全漏洞,CVE编号是CVE-2025-23107,属于高危级别。 漏洞出现在Exynos NPU驱动中,具体是因为缺少长度检查,导致缓冲区溢出写入,可以被本地攻击者利用来提升权限。文章还提到了受影响的版本和芯片型号,以及CVSS评分系统。 用户的需求很明确,就是简明扼要地总结内容。所以我要抓住关键点:漏洞名称、影响的产品、问题原因、攻击后果、评分和修复情况。 接下来,我需要用简洁的语言把这些信息整合起来,确保不超过100字。可能的结构是:产品名称+漏洞名称+问题原因+影响+评分+修复状态。 这样就能满足用户的要求了。 </think> 三星Galaxy S24+中的Exynos NPU驱动存在高危漏洞(CVE-2025-23107),因缺少长度检查导致缓冲区溢出写入,可被本地攻击者利用以实现权限提升。CVSS3.1评分为7.8(高危),已发布修复补丁。 2025-6-1 00:0:0 Author: starlabs.sg(查看原文) 阅读量:3 收藏

Advisory June 1, 2025 By Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng 2 min read

CVE: CVE-2025-23107

Affected Versions: Samsung Galaxy S24+ (samsung/e2sxxx/e2s:14/UP1A.231005.007/S926BXXS3AXGD:user/release-keys); Samsung Exynos 1480, 2400

CVSS3.1: 7.8 (High) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Summary

Product Samsung Exynos NPU Driver
Vendor Samsung
Severity High — a local attacker within untrusted_app SELinux context may exploit this to achieve local privilege escalation
Affected Versions Samsung Galaxy S24+ (Android 14); Exynos 1480, 2400
Tested Versions Samsung Galaxy S24+ (S926BXXS3AXGD)
CVE Identifier CVE-2025-23107
CVE Description A missing length check in the Samsung Exynos NPU driver leads to out-of-bounds writes, exploitable for local privilege escalation
CWE Classification(s) CWE-787: Out-of-Bounds Write

CVSS3.1 Scoring System

Base Score: 7.8 (High) Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Metric Value
Attack Vector (AV) Local
Attack Complexity (AC) Low
Privileges Required (PR) Low
User Interaction (UI) None
Scope (S) Unchanged
Confidentiality (C) High
Integrity (I) High
Availability (A) High

Product Background

The Samsung Galaxy S24+ features a Neural Processing Unit (NPU) integrated into either the Snapdragon 8 Gen 3 or Exynos 2400 chipset depending on the market. The NPU accelerates on-device AI workloads including camera processing, real-time translation, and generative photo editing. The NPU kernel driver manages session state, memory allocation, and queue management on behalf of userspace applications.

Technical Details

In fill_vs4l_buffer, it didn’t check if user provided array of buffer in container is smaller than the actual size of buffer in queue_list.

static void fill_vs4l_buffer(struct npu_queue_list *queue_list, struct vs4l_container_list *c, bool fill)
{
    	/* sync buffers */
	for (i = 0; i < queue_list->count; ++i) {
		container = &queue_list->containers[i];
		k = container->count;
		for (j = 0; j < k; ++j)
			c->containers[i].buffers[j].reserved = container->buffers[j].reserved;
	}

If c->count is smaller than queue->list->count, or c->containers[i].count is smaller than queue_list->containers[i].count it will leads to ARB write or OOB write.

Credit

Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan and Pan Zhenpeng of STAR Labs SG Pte. Ltd.

Timeline


文章来源: https://starlabs.sg/advisories/25/25-23107/
如有侵权请联系:admin#unsafe.sh