CVE-2017-18644
Description
An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is a muic_set_reg_sel heap-based buffer overflow during the reading of MUIC register values. The Samsung ID is SVE-2017-10011 (December 2017).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A heap-based buffer overflow in Samsung mobile MUIC register reading (L/M/N) allows memory corruption, exploitable via a malicious USB accessory.
Vulnerability
The vulnerability is a heap-based buffer overflow in the muic_set_reg_sel function during the reading of MUIC (Micro-USB Integrated Circuit) register values. This issue affects Samsung mobile devices running Android Lollipop (5.1), Marshmallow (6.x), and Nougat (7.x). The overflow occurs when processing specially crafted MUIC register values, potentially controlled by a connected USB device or charger. Samsung ID SVE-2017-10011 (December 2017) was assigned. The official description confirms the heap overflow but does not provide a root cause analysis [1].
Exploitation
An attacker would need physical access or the ability to connect a malicious USB accessory (e.g., a charger or OTG device) to the target device. No authentication is required as the MUIC driver is accessed at the kernel level during USB detection and charging. The sequence involves the device attempting to read a corrupted MUIC register value, which triggers the overflow in the secure memory heap, potentially leading to memory corruption and code execution in the kernel context.
Impact
Successful exploitation can lead to memory corruption, potentially allowing arbitrary kernel code execution. The attacker could gain elevated privileges (kernel level), leading to complete compromise of confidentiality, integrity, and availability of the device. Information disclosure or persistent device takeover are possible outcomes.
Mitigation
Samsung addressed this issue as part of their monthly security update program, with the fix released in December 2017. Users should ensure their device is updated to the latest security patch level. The Samsung Mobile Security website provides update details [1]. No workaround is available; users must apply the vendor-provided patch. Devices running Android 8.0 (Oreo) or later are not affected.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Samsung/mobile devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- security.samsungmobile.com/securityUpdate.smsbmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.