CVE-2023-21506
Description
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds write in Samsung Blockchain Keystore bc_tui trustlet allows local arbitrary code execution via crafted BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command.
Vulnerability
An out-of-bounds write vulnerability exists in the bc_tui trustlet of Samsung Blockchain Keystore prior to version 1.3.12.1. The flaw is triggered by processing a crafted BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command, leading to a write beyond allocated memory boundaries.
Exploitation
An attacker requires local access to the device and the ability to send a malicious BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command to the bc_tui trustlet. No further authentication or user interaction is specified in the available references, though the command must reach the trustlet, typically requiring kernel-level or privileged access on the device.
Impact
Successful exploitation allows a local attacker to execute arbitrary code within the context of the bc_tui trustlet, which operates in the TrustZone secure world. This can lead to a full compromise of sensitive data managed by the Blockchain Keystore, such as cryptographic keys, and may allow further privilege escalation within the secure environment.
Mitigation
Samsung released the fix in version 1.3.12.1 of the Blockchain Keystore. Users should update to this version or later via Samsung's security update process, as described in the Samsung Mobile Security advisory published in May 2023 [1]. No workarounds are disclosed for unpatched devices.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <1.3.12.1
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.