← All Advisories

Samsung Exynos Wi-Fi driver concurrent ioctl race triggers use-after-free condition

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2025-54602

Key Details

CVECVE-2025-54602
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Samsungexynos_980_firmware
Samsungexynos_850_firmware
Samsungexynos_1080_firmware
Samsungexynos_1280_firmware
Samsungexynos_1330_firmware
Samsungexynos_1380_firmware
Samsungexynos_1480_firmware
Samsungexynos_1580_firmware
Samsungexynos_w1000_firmware
Samsungexynos_w920_firmware
Samsungexynos_w930_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race condition by invoking an ioctl function concurrently from multiple threads. (NVD)

What to Do

Monitor Samsung's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-54602
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-54602
Vendor advisoryhttps://semiconductor.samsung.com/support/quality-support/product-security-updates/