VYPR
Unrated severityNVD Advisory· Published Aug 10, 2023· Updated Oct 10, 2024

CVE-2023-30689

CVE-2023-30689

Description

Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Out-of-bounds write in Samsung libsec-ril allows local attacker arbitrary code execution; fixed in SMR Aug-2023 Release 1.

Vulnerability

An out-of-bounds write vulnerability exists in the BuildOemEmbmsGetSigStrengthResponse function of libsec-ril on Samsung devices. The issue affects all versions prior to the SMR Aug-2023 Release 1 [1]. The vulnerability is triggered when processing a crafted input to the RIL component, leading to a heap buffer overflow.

Exploitation

An attacker requires local access to the device, either through a malicious application or by gaining a foothold. No additional privileges are needed, as the vulnerable function is callable from user space. The attacker sends a specially crafted signal strength request that causes an out-of-bounds write within the BuildOemEmbmsGetSigStrengthResponse function.

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the libsec-ril process, which runs as a system-level service. This can lead to full compromise of the device, including data exfiltration, installation of malware, or denial of service.

Mitigation

The vulnerability is patched in Samsung's Security Maintenance Release (SMR) for August 2023 [1]. Users should ensure their devices have applied the latest security updates from Samsung. No workarounds are available; the only mitigation is to install the update.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.