Sceawere
Vulnerability Detail
CVE-2023-37366UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Exynos Shannon SM Infinite Loop
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.8
- Creation Date
- 1h ago
- Vendor
- Samsung
- Product
- Exynos 850 firmware
- Attack Type
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.8",
"pubDate": "2026-09-14T06:16:53.907Z",
"pubdate": "2026-09-14T06:16:53.907Z",
"executiveSummary": "A critical vulnerability exists within the Shannon SM Task of various Samsung Exynos processors, including Mobile, Automotive, and Modem chipsets.\nThe flaw stems from improper handling of a loop construct characterized by an unreachable exit condition.\nThis vulnerability allows an attacker to trigger an infinite loop state, effectively causing a Denial of Service (DoS) for the affected service.\nThe impact includes the loss of functionality for the targeted Shannon SM component, potentially leading to system-wide instability or modem-related outages.\nExploitation requires the delivery of a specifically crafted, malformed SM message to the processing component.\nAffected products include a wide range of Exynos platforms such as Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123.\nGiven the nature of the Shannon task, this vulnerability poses a significant risk to the availability of critical communication sub-systems.",
"technicalDetails": "The vulnerability is localized within the Shannon SM (System Manager/Message) Task, which acts as a core component for handling communication protocols and inter-processor messaging within the Exynos architecture.\nThe root cause is a logic error in the handling of a control flow loop. Specifically, the implementation contains a loop structure that lacks a valid, reachable exit condition under certain input scenarios.\nWhen the SM Task receives a malformed SM message specifically crafted to trigger this logical flaw, the program execution enters a non-terminating loop.\nThe exploitation process follows a sequential flow: first, the attacker identifies a mechanism to deliver a malformed SM message to the Shannon SM interface. Upon ingestion of this malicious payload, the parsing or processing logic encounters the flawed loop construct.\nBecause the exit condition is unreachable, the task enters a busy-wait or infinite execution state. This state consumes computational resources allocated to the task, effectively blocking the processing of any subsequent legitimate tasks or messages.\nAs the Shannon task is responsible for critical modem and system services, the exhaustion of these resources results in the loss of service availability for the affected modem or processor functions. This constitutes a Denial of Service attack against the task level.\nThe vulnerability resides in the firmware level of the Exynos processor's baseband/modem management logic. Because the SM task operates at a low level within the chipset's execution environment, a hung thread or infinite loop at this level frequently necessitates a full reset of the affected hardware component to restore functionality.\nThere are no specific authentication requirements mentioned for the submission of the malicious SM message, suggesting that the interface may be reachable by any component capable of communicating with the Shannon SM Task, depending on the system's internal isolation and inter-process communication (IPC) architecture.\nPost-exploitation impact is characterized by persistent denial of service of the modem or related system features. The attacker effectively forces the system to hang or crash the specific task, requiring manual intervention or watchdog timer intervention to recover, thereby disrupting connectivity or peripheral communication handled by the affected Shannon task."
}