QID 610454

Date Published: 2022-12-13

QID 610454: Google Android December 2022 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2021-35122, CVE-2022-20472, CVE-2022-20473, CVE-2022-20411, CVE-2022-20498,CVE-2021-1050, CVE-2021-39661, CVE-2022-32602, CVE-2021-35109, CVE-2021-35108, CVE-2021-35135, CVE-2021-35132, CVE-2022-25671, CVE-2022-33237, CVE-2022-33239, CVE-2022-25724, CVE-2022-25743, CVE-2022-25741, CVE-2022-38690, CVE-2022-2984, CVE-2022-38676, CVE-2022-38672, CVE-2022-39105, CVE-2022-38673, CVE-2022-2985, CVE-2022-38669, CVE-2022-38670, CVE-2022-20502, CVE-2021-39617, CVE-2021-39795, CVE-2022-20124, CVE-2022-20442, CVE-2022-20444, CVE-2022-20470, CVE-2022-20474, CVE-2022-20475, CVE-2022-20477, CVE-2022-20485, CVE-2022-20486, CVE-2022-20491, CVE-2022-20611, CVE-2021-0934, CVE-2022-20449, CVE-2022-20476, CVE-2022-20482, CVE-2022-20500, CVE-2022-20496, CVE-2022-20469, CVE-2022-20144, CVE-2022-20240, CVE-2022-20478, CVE-2022-20479, CVE-2022-20480, CVE-2022-20484, CVE-2022-20487, CVE-2022-20488, CVE-2022-20495, CVE-2022-20501, CVE-2022-20471, CVE-2022-20483, CVE-2022-20497, CVE-2021-39673, CVE-2022-20131, CVE-2022-20466

Affected Products :
Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Fold3 5G, Galaxy Z Fold4, Galaxy Z Flip, Galaxy Z Flip 5G, Galaxy Z Flip3 5G, Galaxy Z Flip4, W23, W23 flip Galaxy S10 Lite Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G, Galaxy S21 5G, Galaxy S21+ 5G, Galaxy S21 Ultra 5G, Galaxy S21 FE 5G, Galaxy S22, Galaxy S22+, Galaxy S22 Ultra Galaxy Note10 Lite, Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G Enterprise Models: Galaxy A52, Galaxy A52 5G, Galaxy A52s 5G, Galaxy A53 5G, Galaxy Xcover Pro, Galaxy Xcover5, Galaxy Xcover6 Pro

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Refer to Samsung Security advisory SMR-December-2022 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-December-2022 Android URL Logo security.samsungmobile.com/securityUpdate.smsb