SB20260202109 - Multiple vulnerabilities in Samsung products



SB20260202109 - Multiple vulnerabilities in Samsung products

Published: February 2, 2026

Security Bulletin ID SB20260202109
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58340)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/send_delts write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


2) Input validation error (CVE-ID: CVE-2025-59439)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect handling of NAS Registration messages. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


3) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58348)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/confg_tspec write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


4) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58346)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/send_addts write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


5) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58345)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/ap_certif_11ax_mode write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


6) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58344)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/conn_log_event_burst_to_us write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


7) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58343)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/create_tspec write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


8) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58342)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/uapsd write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


9) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58341)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/ap_cert_disable_ht_vht write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


10) Uncontrolled Memory Allocation (CVE-ID: CVE-2025-58347)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncontrolled memory allocation in /proc/driver/unifi0/p2p_certif write operation. A remote attacker can cause a denial of service (DoS) condition on the target system.


Remediation

Install update from vendor's website.