CVE-2023-30689
Description
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds write in Samsung libsec-ril allows local attacker arbitrary code execution; fixed in SMR Aug-2023 Release 1.
Vulnerability
An out-of-bounds write vulnerability exists in the BuildOemEmbmsGetSigStrengthResponse function of libsec-ril on Samsung devices. The issue affects all versions prior to the SMR Aug-2023 Release 1 [1]. The vulnerability is triggered when processing a crafted input to the RIL component, leading to a heap buffer overflow.
Exploitation
An attacker requires local access to the device, either through a malicious application or by gaining a foothold. No additional privileges are needed, as the vulnerable function is callable from user space. The attacker sends a specially crafted signal strength request that causes an out-of-bounds write within the BuildOemEmbmsGetSigStrengthResponse function.
Impact
Successful exploitation allows the attacker to execute arbitrary code with the privileges of the libsec-ril process, which runs as a system-level service. This can lead to full compromise of the device, including data exfiltration, installation of malware, or denial of service.
Mitigation
The vulnerability is patched in Samsung's Security Maintenance Release (SMR) for August 2023 [1]. Users should ensure their devices have applied the latest security updates from Samsung. No workarounds are available; the only mitigation is to install the update.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: < SMR Aug-2023 Release 1
- Range: SMR Aug-2023 Release 1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.