{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-25372",
  "revision": 1,
  "title": "Samsung — the processor driver reaches out of range",
  "summary": "An improper boundary check in the signal processor driver (DSP) on Samsung devices permits memory access outside the range it should hold to. It was fixed in the same March 2021 release as the driver's loading flaw.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 6.7,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.00804,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-06-29",
    "prerequisites": "Code running on the device able to reach the processor driver."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Install the March 2021 Samsung security update or later; the same release carries the other driver flaw published beside this one.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-25372",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-25372",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-25372",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25372",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://security.samsungmobile.com"
    },
    {
      "type": "vendor_advisory",
      "url": "https://security.samsungmobile.com/securityUpdate.smsb"
    }
  ],
  "published_at": "2021-03-26T19:15:12.303Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "samsung",
    "android",
    "dsp",
    "out-of-bounds",
    "mobile",
    "kev"
  ]
}
