-
CVE-2024-45551: Weak Authentication in HLOS (16-04-2025)
NVD Published Date: 04/07/2025 NVD Last Modified: 04/07/2025 Preface: Released on September 3, 2024 as Android 15. Android 16, Internal codename as Baklava, released on 2nd April 2025. Background: The core of the Android OS operating system is the Android Open Source Project (AOSP), which is free open source software (FOSS) licensed primarily under the…
-
CVE-2024-10929: Staying alert! Spectre-BSE exploits affects ARM® Cortex®-A72 (revisions prior to r1p0), Cortex-A73 and Cortex-A75. (15-04-2025)
Preface: The Cortex-A75 is still being used by manufacturers today. For instance, UNISOC and MediaTek continue to incorporate Cortex-A75 cores in their chipsets. These processors are found in various mid-range and entry-level devices, providing a balance of performance and efficiency. Background: Branch Status Eviction (BSE) is a vulnerability related to the Spectre class of security…
-
About the mysterious mask of CVE-2025-22429 (14-4-2025)
Preface: The reason why an unparcel error involving Parcel and BaseBundle is considered a critical Common Vulnerabilities and Exposures (CVE) is due to the potential security risks it poses. Specifically, such errors can lead to: Data Corruption, Security Vulnerabilities and Denial of Service (DoS). Background: BaseBundle[.]java in Android is a class that provides a mapping…
-
CVE-2025-21443: Memory corruption while processing message content in eAVB. (13th Apr 2025)
Preface: The Snapdragon SA8540P SoC and SA9000P AI accelerator are designed to work together seamlessly, particularly in advanced driver-assistance systems (ADAS) like GM’s Ultra Cruise. The buffer sharing design between these components is crucial for efficient data processing and low-latency performance. In automotive Ethernet Audio Video Bridging (eAVB), processors handle various types of message content…
-
CVE-2025-21425: Memory corruption may occur due to improper access control in HAB process. (10th Apr 2025)
Announcement on January 6, 2022: GM and Qualcomm showcase collaboration at CES that brings first dedicated Snapdragon system-on-chips to GM’s upcoming advanced driver assistance system for fast, robust data processing. Preface: When the Snapdragon SA8540P SoC and SA9000P AI accelerator work together, they typically use a coordinated boot process. Each component has its own firmware,…
-
About: CVE-2024-0179 – SMM Callout vulnerability and CVE-2024-21925 – Improper input validation (9th April 2025)
Preface: An SMM Callout is a type of vulnerability found in System Management Mode (SMM) code. This occurs when SMM code calls a function located outside of the System Management RAM (SMRAM) boundaries. The most common scenario is when an SMI (System Management Interrupt) handler tries to invoke a UEFI boot service or runtime service…
-
CVE-2025-0050: Arm Mali GPU Userspace Driver could allow an Out-of-Bounds access (8th April 2025)
Preface: A Use-After-Free (UAF) vulnerability occurs when a program continues to access memory after it has been freed. This can lead to unpredictable behavior, crashes, or even allow an attacker to execute arbitrary code. For example, if a program frees a block of memory but later tries to read or write to that memory, it…
-
System Management Mode (SMM) does not follow best practices. The impact extends beyond the desktop to HPC as well! (7th Apr 2025)
Preface: In the realm of High Performance Computing (HPC), processors that use the x86 architecture typically support System Management Mode (SMM). This includes: -Intel Xeon Processors: Widely used in HPC systems, Intel Xeon processors support SMM for managing system-wide tasks such as power management and hardware control. -AMD EPYC Processors: AMD EPYC processors, including the…
-
CVE-2025-3305: code projects IKUN_Library – Improper access control and incorrect privilege assignment (6th Apr 2025)
Preface: Investment bank use Spring Boot for developing microservices and REST APIs. Hospitality utilizes Spring Boot for various backend services. Automotive company Uses Spring Boot for configuration management and service discovery. Background: IKUN_Library 1.0 is a library management system developed using SpringBoot and MyBatis. It provides functionalities for managing books, readers, and borrowing records. The…
-
About AMD Ryzen™ AI Software: CVE-2025-0014, CVE-2024-36337,CVE-2024-36336 & CVE-2024-36328 (3th Apr 2025)
Preface: The Ryzen 7000 desktop and laptop chips were introduced in 2023. Alongside the main x86 CPU, Ryzen 7000 has a new type of coprocessor, a Neural Processing Unit (NPU), based on the XDNA™ AI Engine architecture. This new NPU is called Ryzen AI. Background: 1.Install NPU Drivers 2.Download the NPU driver installation package NPU…