{"id":"CVE-2025-21071","details":"Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.","modified":"2026-03-12T17:39:15.924242Z","published":"2025-11-05T06:15:33.337Z","references":[{"type":"ADVISORY","url":"https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=11"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"13.0-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-apr\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-apr\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-apr\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-apr\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-aug\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-aug\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-aug\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-aug\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-dec\\-2021\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-dec\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-dec\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-dec\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-feb\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-feb\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-feb\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-feb\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jan\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jan\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jan\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jan\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jul\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jul\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jul\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jul\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jun\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jun\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jun\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-jun\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-mar\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-mar\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-mar\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-mar\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-may\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-may\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-may\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-may\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-nov\\-2021\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-nov\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-nov\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-nov\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-oct\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-oct\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-oct\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-oct\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-sep\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-sep\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-sep\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"13.0-smr\\-sep\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-apr\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-apr\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-apr\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-apr\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-aug\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-aug\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-aug\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-aug\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-dec\\-2021\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-dec\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-dec\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-dec\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-feb\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-feb\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-feb\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-feb\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jan\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jan\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jan\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jan\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jul\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jul\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jul\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jul\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jun\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jun\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jun\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-jun\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-mar\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-mar\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-mar\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-mar\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-may\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-may\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-may\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-may\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-nov\\-2021\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-nov\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-nov\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-nov\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-oct\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-oct\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-oct\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-oct\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-sep\\-2022\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-sep\\-2023\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-sep\\-2024\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"14.0-smr\\-sep\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-apr\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-aug\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-jul\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-jun\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-mar\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-may\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-oct\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0-smr\\-sep\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"16.0-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"16.0-smr\\-aug\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"16.0-smr\\-oct\\-2025\\-r1"}]},{"events":[{"introduced":"0"},{"last_affected":"16.0-smr\\-sep\\-2025\\-r1"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21071.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"}]}