Samsung Exynos NULL Pointer Dereference Vulnerability in NPU Driver

Vulnerability

A NULL pointer dereference vulnerability has been identified in the NPU (Neural Processing Unit) driver of Samsung Mobile Processor Exynos, affecting versions through July 2025. The issue arises in the 'npu_vertex_profileoff' function, where 'profiler.node' is improperly handled, leading to potential exploitation.

Impact

Exploitation of this vulnerability causes a NULL pointer dereference, which can lead to a denial-of-service condition by causing the system to crash or become unresponsive.

Added: Nov 4, 2025, 5:22 PM
Updated: Nov 4, 2025, 9:32 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.