VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18655

CVE-2017-18655

Description

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-based buffer overflow with resultant memory corruption in a trustlet. The Samsung IDs are SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892 (August 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack-based buffer overflow in a Samsung trustlet on M(6.0) and N(7.x) devices causes memory corruption, leading to arbitrary code execution in the trustlet context.

Vulnerability

The vulnerability, tracked as CVE-2017-18655, is a stack-based buffer overflow in a trustlet on Samsung mobile devices running Android M (6.0) and N (7.x). The overflow results in memory corruption. This issue was addressed in Samsung's August 2017 security update (Samsung IDs SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892). [1]

Exploitation

An attacker with local access to the device could potentially exploit this vulnerability. The exact attack vector and required privileges are not fully disclosed in the available references, but a stack-based buffer overflow in a trustlet suggests the attacker could send a crafted input to the trustlet component, leading to buffer overflow and memory corruption. [1]

Impact

Successful exploitation could result in memory corruption and potentially arbitrary code execution within the trustlet context. A trustlet is a trusted application running in ARM TrustZone, meaning compromise could allow the attacker to gain elevated privileges or access sensitive data protected by the trusted execution environment (TEE). [1]

Mitigation

Samsung released security updates in August 2017 to fix this vulnerability. Users should ensure their devices are running the latest Android security patch level. There is no known workaround besides applying the patch. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.