CVE-2023-21509
Description
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds write in Samsung Blockchain Keystore bc_tui trustlet via BC_TUI_CMD_UPDATE_SCREEN allows local code execution before 1.3.12.1.
Vulnerability
An out-of-bounds write vulnerability exists in the bc_tui trustlet of Samsung Blockchain Keystore when processing the BC_TUI_CMD_UPDATE_SCREEN command. This occurs in versions prior to 1.3.12.1. The flaw allows writing beyond the allocated buffer boundaries during screen update handling.
Exploitation
The attacker must have local access to the device and be able to send crafted BC_TUI_CMD_UPDATE_SCREEN commands to the bc_tui trustlet. No additional authentication or user interaction is required beyond local execution rights. The exact exploitation steps are not detailed in the available references, but the out-of-bounds write condition can be triggered by supplying a command with manipulated size or offset parameters.
Impact
Successful exploitation allows the local attacker to execute arbitrary code within the context of the trustlet, potentially leading to full compromise of the Blockchain Keystore's security functions. This could result in disclosure or modification of sensitive cryptographic material stored by the keystore.
Mitigation
Samsung has addressed this vulnerability in Blockchain Keystore version 1.3.12.1, released in May 2023 [1]. Users should update to this version or later via Samsung's security update process. No workaround other than applying the update is documented.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <1.3.12.1
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.