VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18651

CVE-2017-18651

Description

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is an Integer Overflow in process_M_SetTokenTUIPasswd during handling of a trusted application, leading to memory corruption. The Samsung IDs are SVE-2017-9008 and SVE-2017-9009 (October 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in Samsung mobile TZ manager’s process_M_SetTokenTUIPasswd causes memory corruption on devices with M(6.x) and N(7.x).

Vulnerability

An integer overflow vulnerability exists in the process_M_SetTokenTUIPasswd function of the Samsung mobile trusted application (TZ) manager. This flaw affects Samsung mobile devices running Android M (6.x) and N (7.x) software. The overflow occurs during the handling of a trusted application, leading to memory corruption. Samsung IDs SVE-2017-9008 and SVE-2017-9009 document the issue, which was addressed in October 2017 [1].

Exploitation

An attacker would need the ability to trigger the processing of a crafted trusted application on an affected device. The vulnerability is reachable without physical access but requires the ability to install or manipulate a trusted application that invokes the vulnerable function. The integer overflow in process_M_SetTokenTUIPasswd then leads to memory corruption.

Impact

Successful exploitation results in memory corruption, which can potentially lead to arbitrary code execution within the TZ (TrustZone) context. This could allow an attacker to gain elevated privileges, compromise the secure environment of the device, and access sensitive data protected by the trusted execution environment.

Mitigation

Samsung published security updates in October 2017 to address this issue [1]. Users should ensure their devices have received the latest security patches from Samsung. Devices running Android versions M (6.x) and N (7.x) that have applied the October 2017 update or later are no longer vulnerable.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.