CVE-2023-21492

Samsung Mobile Devices

Published 4 May 2023 · updated 17 Jun 2026 · Analyzed

4.4 Medium · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 19 May 2023, with a remediation deadline of 9 Jun 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

References