CVE-2025-54331

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_1380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:*

History

07 Nov 2025, 12:56

Type Values Removed Values Added
CPE cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_1380_firmware:*:*:*:*:*:*:*:*
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-54331/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-54331/ - Vendor Advisory
First Time Samsung exynos 1380 Firmware
Samsung exynos 1380
Samsung

06 Nov 2025, 19:45

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 17:16

Updated : 2025-11-07 12:56


NVD link : CVE-2025-54331

Mitre link : CVE-2025-54331

CVE.ORG link : CVE-2025-54331


JSON object : View

Products Affected

samsung

  • exynos_1380_firmware
  • exynos_1380
CWE
CWE-822

Untrusted Pointer Dereference