SB2025101018 - Multiple vulnerabilities in Samsung products
Published: October 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) NULL pointer dereference (CVE-ID: CVE-2024-55568)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the UL2 component. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
2) Improper access control (CVE-ID: CVE-2025-48025)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access control in log file within Wifi driver. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
3) Input validation error (CVE-ID: CVE-2025-26782)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of RLC AM PDUs within the L2 component. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
4) Input validation error (CVE-ID: CVE-2025-26781)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of RLC AM PDUs within the L2 component. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://semiconductor.samsung.com/content/semiconductor/global/support/quality-support/product-security-updates/cve-2024-55568/
- https://semiconductor.samsung.com/content/semiconductor/global/support/quality-support/product-security-updates/cve-2025-48025/
- https://semiconductor.samsung.com/content/semiconductor/global/support/quality-support/product-security-updates/cve-2025-26782/
- https://semiconductor.samsung.com/content/semiconductor/global/support/quality-support/product-security-updates/cve-2025-26781/