CVE-2025-54332

7.5

Samsung · Exynos 1380

A NULL pointer dereference vulnerability in the NPU component of Samsung Exynos 1380 processors allows for potential denial of service via the npu_vertex_profileoff function.

Executive summary

A NULL pointer dereference flaw in the Samsung Exynos 1380 processor NPU creates a high risk of service disruption.

Vulnerability

The vulnerability is a NULL pointer dereference occurring within the npu_vertex_profileoff function of the Neural Processing Unit (NPU). Based on the CVSS vector (AV:N/AC:L/PR:N/UI:N), this flaw is accessible to unauthenticated remote attackers.

Business impact

The primary impact of this vulnerability is a denial of service, which can lead to system instability or total device crash. With a CVSS score of 7.5, this high-severity issue necessitates prompt attention, particularly in enterprise environments where Samsung hardware is integrated into critical mobile workflows, as it could lead to significant operational downtime.

Remediation

Immediate Action: Consult the official Samsung Semiconductor security update portal to identify and apply the relevant firmware or driver patches for the Exynos 1380 processor.

Proactive Monitoring: Monitor system logs for repeated NPU driver crashes or unexpected device reboots that may indicate an attempt to trigger this vulnerability.

Compensating Controls: Ensure that security hardening policies are enforced on devices to limit exposure to untrusted network traffic that could reach the vulnerable processor interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the nature of the flaw, organizations utilizing devices powered by the Samsung Exynos 1380 processor should prioritize the deployment of vendor security updates. While no active exploitation is confirmed, the potential for denial of service makes patching a critical component of maintaining system availability and integrity.

More Samsung CVEs

Sources