Disclosure summary
There is an ION memory buffer type confusion vulnerability in the Exynos ION kernel driver. The vulnerability can cause zero initialised memory to be treated as a valid pointer and
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Taszk Labs on taszk.io labs · RSS-ee0ff20322b4f7a5f023f60849e123c9e57
Open original source · Updated Dec 12, 2021
CVE-2021-25458: Kernel NULL Pointer Dereference in Exynos ION Implementation
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- labs.taszk.io — Publisher advisory
PUBLISHED 2021-12-12T19:00:00-05:00
MODIFIED 2021-12-12T19:00:00-05:00
INGESTED 2026-10-08T12:20:18-04:00