VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18691

CVE-2017-18691

Description

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) software. There are multiple Buffer Overflows in TSP sysfs cmd_store. The Samsung ID is SVE-2016-7500 (January 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple buffer overflows in TSP sysfs cmd_store on Samsung Exynos8890 devices with Android 6.0 and 7.0.

Vulnerability

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) software. There are multiple buffer overflows in TSP sysfs cmd_store. The Samsung ID is SVE-2016-7500 (January 2017). Affected versions are those running Android 6.0 and 7.0 on Exynos8890 chipsets.

Exploitation

The exploitation requires the attacker to have local access to the device or ability to interact with the TSP sysfs interface. The specific conditions and sequence of steps are not detailed in the available references. However, buffer overflow vulnerabilities in kernel sysfs interfaces can typically be triggered by writing overly long inputs to the vulnerable sysfs file.

Impact

Successful exploitation could lead to a denial of service or potentially arbitrary code execution in the kernel context, depending on the nature of the buffer overflow. The exact impact is not explicitly stated in the available references.

Mitigation

Samsung has addressed this issue in security updates. According to the Samsung Mobile Security portal [1], users should apply the latest security patches. The specific fixed version is not mentioned in the available references. Users are advised to keep their devices updated with the latest Samsung security patch level.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.