VYPR
Unrated severityNVD Advisory· Published Mar 23, 2023· Updated Feb 25, 2025

CVE-2023-26496

CVE-2023-26496

Description

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Memory corruption in Samsung Exynos baseband modems due to improper parameter length checking in SDP fmtp attribute parsing.

Vulnerability

A memory corruption vulnerability exists in the Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. The issue occurs in the Session Description Protocol (SDP) module when parsing the fmtp attribute. The modem fails to properly check the length of the parameter, leading to a buffer overflow or similar memory corruption. Affected versions include all firmware variants for the listed chipsets prior to the security update referenced in [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted SDP message to the target device's modem. The attacker does not require authentication but must be able to deliver the malicious SDP data over the air (e.g., via a malicious base station or a crafted SIP/VoLTE call). No user interaction is needed beyond the device receiving the crafted message. The improper length check allows the attacker to overwrite adjacent memory regions.

Impact

Successful exploitation results in memory corruption within the modem firmware. This can lead to denial of service (modem crash or reboot) or potentially arbitrary code execution at the modem privilege level. The compromise could allow an attacker to intercept or manipulate cellular communications, or use the modem as a pivot point for further attacks on the application processor.

Mitigation

Samsung has acknowledged the issue and provides product security updates through its support portal [1]. As of the publication date (2023-03-23), specific fixed firmware versions have not been publicly detailed. Users should apply the latest modem firmware updates from their device manufacturer or carrier. No workaround is available for unpatched devices.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.