CVE-2023-41112
Description
A buffer copy without size check in Samsung Exynos RLC task/module leads to a denial-of-service via abnormal termination.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer copy without size check in Samsung Exynos RLC task/module leads to a denial-of-service via abnormal termination.
Vulnerability
A buffer copy without checking the size of the input exists in the RLC task and RLC module of multiple Samsung Exynos processors and modems. Affected products include Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123 [1]. The issue occurs when the RLC component copies data into a buffer without verifying that the destination buffer is large enough to hold the source data.
Exploitation
An attacker must be able to send crafted network traffic or otherwise supply input that reaches the vulnerable RLC module. The exact prerequisite level of access or network position is not detailed in the available references; however, a remote unauthenticated attacker could potentially trigger the condition by sending a malformed packet to the device [1]. No user interaction is required if the device automatically processes incoming RLC frames.
Impact
Successful exploitation results in abnormal termination of the mobile phone (denial of service). The impact is limited to availability; there is no current evidence of code execution or information disclosure in the published references [1].
Mitigation
Samsung has addressed this vulnerability via a security update. Users are advised to apply the latest firmware updates from their device manufacturer. The exact patched version numbers per chipset are not individually listed in the advisory, but users should consult the Samsung Product Security Updates page [1] for the appropriate patch level. No upstream workaround other than updating is available.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Samsung/Processor, Wearable Processor, Automotive Processor, and Modemdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.