Connect with us

Updates

Samsung September 2021 Security Patch Details – New Fixes (CVE/SVE)

Published

on

Samsung Security Patch Update

Though a bit late, but Samsung has finally released its September 2021 One UI security patch details alongside the Android patches by Google. As always, the newly published security bulletin brings detailed information including different levels of CVEs such as critical, high and moderate as well as Samsung SVEs.

If we go with Samsung’s official Firmware Updates support page, the September 2021 security patch comes with fixes for 3 critical, 29 high, and 14 moderate CVEs from Google. At the same time, 2 CVEs had already been included in previous updates, while 9 are not applicable on Galaxies.

Below, you can see the CVEs that will be fixed on your Samsung Galaxy device after upgrading to September 2021 security patch.

Critical

  • CVE-2021-1972, CVE-2021-1976, CVE-2021-0687

High

  • CVE-2021-28375, CVE-2020-14381, CVE-2021-0582, CVE-2021-0578, CVE-2021-0579, CVE-2021-0580, CVE-2021-0581, CVE-2021-30261, CVE-2021-30260, CVE-2021-1939, CVE-2021-1947, CVE-2021-1904, CVE-2021-0639, CVE-2019-10581, CVE-2021-0518, CVE-2021-0595, CVE-2021-0683, CVE-2021-0684, CVE-2021-0685, CVE-2021-0688, CVE-2021-0686, CVE-2021-0689, CVE-2021-0690, CVE-2021-0598, CVE-2021-0692, CVE-2021-0428, CVE-2021-0644, CVE-2021-0682, CVE-2021-0693

Moderate

  • CVE-2021-0565, CVE-2021-0556, CVE-2021-0562, CVE-2021-0566, CVE-2021-0536, CVE-2021-0537, CVE-2021-0538, CVE-2021-0539, CVE-2021-0547, CVE-2021-0548, CVE-2021-0553, CVE-2021-0549, CVE-2021-0552, CVE-2021-0691

Already included in previous updates

  • CVE-2021-3347, CVE-2021-0564

Not applicable to Samsung devices

  • CVE-2021-1919, CVE-2021-1916, CVE-2021-1920, CVE-2021-0573, CVE-2021-0574, CVE-2021-0576, CVE-2021-1914, CVE-2021-1978, CVE-2020-3633

Samsung Galaxy Security Update

Join Sammy Fans on Telegram

Aside from CVE fixes, Samsung also offers additional security improvements, better known as SVE, especially for the Galaxy consumers. This month, the company bringing repairs for 23 Samsung Vulnerabilities and Exposures (SVE) items. (Some of them mentioned below)

SVE-2021-21619 (CVE-2021-25457): Kernel Information Disclosure in the Vision DSP Kernel Driver

Severity: Moderate

Affected versions: Q(10.0), R(11.0) devices with Exynos 980, 9830, 2100 chipsets

  • An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
  • The patch adds proper input validation in DSP driver.

SVE-2021-21943 (CVE-2021-25450): Path traversal vulnerability in FactoryAirCommandManager

Severity: High

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
  • The patch addresses incorrect implementation of file path validation check logic.

SVE-2021-22094 (CVE-2021-25449): Arbitrary code execution on mediaextractor process

Severity: Moderate

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.
  • The patch adds proper input check to prevent buffer overflow.

SVE-2021-21959 (CVE-2021-25452): Kernel Permanent Denial of Service Vulnerability in the Vision DSP Kernel Driver

Severity: Moderate

Affected versions: Q(10.0), R(11.0) devices with Exynos 980, 9830, 2100 chipsets

  • An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
  • The patch adds proper input check to prevent loading unintended file in path.

SVE-2021-21041 (CVE-2021-25453): Leak Bluetooth information through Broadcast in Bluetooth app

Severity: High

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
  • The patches add proper access control to prevent Bluetooth information leak.

SVE-2021-21620 (CVE-2021-25458): NULL pointer dereference vulnerability in the ION Driver

Severity: Low

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0) devices with Exynos chipsets

  • NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
  • The patch adds proper input check to prevent null pointer dereference.

SVE-2021-22602 (CVE-2021-25459): Improper access control in BlockChainService

Severity: Moderate

Affected versions: Select Q(10.0), R(11.0)

  • An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
  • The patch adds the proper permission check to prevent improper access to BlockchainTZService.

SVE-2021-22603 (CVE-2021-25460): Improper access control in BlockChainService

Severity: Moderate

Affected versions: Select Q(10.0), R(11.0)

  • An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
  • The patch adds the proper permission check to prevent improper access to BlockchainTZService.

SVE-2021-22411 (CVE-2021-25461): APAService Stack Overflow

Severity: Low

Affected versions: O(8.1)

  • An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
  • The patch adds proper length check in APAService.

SVE-2021-21413 (CVE-2021-25451): Sensitive information disclosure in NetworkPolicyManagerService

Severity: Moderate

Affected versions: P(9.0), Q(10.0), R(11.0)

  • A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
  • The patch addresses the intent in NetworkPolicyManagerService to prevent unprivileged access.

SVE-2021-22278 (CVE-2021-25454): OOB read vulnerability in ‘libsaacextractor.so’

Severity: Low

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
  • The patch adds length check code in libsaacextractor library.

SVE-2021-22291 (CVE-2021-25455): OOB read vulnerability in ‘libsaviextractor.so’

Severity: Low

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
  • The patch adds length check code in libsaviextractor library.

SVE-2021-22343 (CVE-2021-25456): OOB read vulnerability in ‘libswmfextractor.so’

Severity: Moderate

Affected versions: O(8.1), P(9.0), Q(10.0), R(11.0)

  • OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.
  • The patch adds length check code in libswmfextractor library.

SVE-2021-21969 (CVE-2021-25462): Null Pointer Dereference vulnerability in the NPU Driver

Severity: Low

Affected versions: P(9.0), Q(10.0), R(11.0) devices with Exynos chipsets

  • NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
  • The patch adds proper input check to prevent null pointer dereference.

Samsung One UI 3.1.1

Released alongside the Galaxy Z Fold 3 and Galaxy Z Flip 3, the One UI 3.1.1 version is making its way to more and more Galaxy devices through software updates. So far, the company’s every flagship smartphone (including older foldables) has started grabbing the One UI 3.1.1 features.

What about Android 12 One UI 4?

Later last month, Samsung teased that the Android 12-based One UI 4 Beta is coming soon for the Galaxy S21 series smartphone owners in South Korea, the US and Germany. The Beta participation had already begun but the company is yet to deliver the first One UI 4 Beta build to the consumers.

James is the lead content creator on Sammy Fans and mostly works on Samsung's firmware section. His first phone was the Galaxy S4 and continues to get new S series devices. Most of the time, James tries to learn about new technologies and gadgets but he also sneaks a bit of free time to nearby rivers and nature.

Samsung

Samsung upscales 4G TDD on Galaxy S23 FE, A34, and A35 in Europe

Published

on

Galaxy S23 FE A34 A35 4G Europe

Samsung has rolled out the updated 4G TDD band support firmware for Galaxy S23 FE, Galaxy A35, and Galaxy A34 smartphones in Europe. The fresh update enhances the 4G TDD band support to better network connectively.

According to the changelog, the new firmware for Samsung Galaxy S23 FE, Galaxy A35, and Galaxy A34 smartphones in Europe updates the Regional 4G TDD band support to deliver better network performance across various European countries.

It is important to note that Galaxy models purchased in Germany cannot receive signals in LTE TDD bands in several countries, including Belgium, Denmark, France, Luxemburg, Netherlands, Austria, Poland, Switzerland, and the Czech Republic.

Moreover, the update also improves the security and stability of the device. It also fixes some issues for error-free services.

Latest Firmware 

  • Galaxy S23 FE – S711BXXU2CXD3
  • Galaxy A35 – A356BXXU1AXBB
  • Galaxy A34 – A346BXXU6BXD2

If you have received the notification of the update then install it now to get a bug-free experience. You can also check the update by visiting the Settings app on your smartphone and opening the Software Update section. Now, click on the Download and Install option.

New Samsung Galaxy S23 firmware updates LTE TDD band support in Europe

Stay up-to-date on Samsung Galaxy, One UI & Tech Stuffs by following Sammy Fans on X/Twitter. You can also discover the latest news, polls, reviews, and new features for Samsung & Google Apps, Galaxy Phones, and the One UI/Android operating system.

Do you like this post? Kindly, let us know on X/Twitter: we love hearing your feedback! If you prefer using other social platforms besides X, follow/join us on Google News, Facebook, and Telegram.

Continue Reading

Samsung

Exynos Samsung Galaxy S21 FE models grab April 2024 update in India

Published

on

Galaxy S21 FE Exynos April 2024 update

After Snapdragon models, Samsung has released an April 2024 security update for Exynos models of the Galaxy S21 FE smartphone in India. Users can identify the latest update through One UI build version G990EXXS8FXD1.

The fresh update improves system security and stability to enhance the overall performance. It protects against security threats by incorporating the latest security patches for Android. Also, it improves some functions to provide a better user experience.

Users of the Exynos Galaxy S21 FE smartphone in India will have to download a 248.39MB package to install the April 2024 security update. The update is based on One UI 6.0 and the company will soon release One UI 6.1 update for this smartphone.

To install the update, users should navigate to the Software Update section found within the device’s Settings. They can select ‘Download and install’ from there to initiate the update process.

Stay up-to-date on Samsung Galaxy, One UI & Tech Stuffs by following Sammy Fans on X/Twitter. You can also discover the latest news, polls, reviews, and new features for Samsung & Google Apps, Galaxy Phones, and the One UI/Android operating system.

Do you like this post? Kindly, let us know on X/Twitter: we love hearing your feedback! If you prefer using other social platforms besides X, follow/join us on Google News, Facebook, and Telegram.

Continue Reading

Samsung

One UI 6.1 Next! Samsung Galaxy S22 gets updated 4G band support in Europe

Published

on

Samsung Galaxy S22 update Europe

Samsung recently began rolling out a software update for its Galaxy devices in Europe, focusing on 4G network compatibility. The update that started releasing with the Galaxy S24 and other recent models is now available for the Galaxy S22 series as well.

Users of Samsung Galaxy S22, Galaxy S22 Plus, and Galaxy S22 Ultra smartphones can identify the new update in Europe through One UI build version S901BXXU8DXD6, S906BXXU8DXD6, and S908BXXU8DXD6 respectively. This update is based on Android 14 and One UI 6.0.

The new update has revised support for the LTE TDD band. For German-purchased devices, the update will disable TDD 4G network support in ten European countries including Belgium, Denmark, Germany, France, Luxembourg, the Netherlands, Austria, Poland, Switzerland, and the Czech Republic.

To check and install the update, open the Settings app >> Software Update >> Download and install.

One UI 6.1 Update

Samsung officially confirmed that the company will release One UI 6.1 update for the Galaxy S22 series along with 5 other Galaxy devices in early May 2024. Moreover, the Canadian network carrier’s schedule also suggested that the Galaxy S22 series, Galaxy Z Fold 4, and Galaxy Z Flip 4 will get a new update with One UI 6.1 starting May 3.

Galaxy S22, Z Fold 4, and Flip 4 to receive Galaxy AI, One UI 6.1 update on May 3

Stay up-to-date on Samsung Galaxy, One UI & Tech Stuffs by following Sammy Fans on X/Twitter. You can also discover the latest news, polls, reviews, and new features for Samsung & Google Apps, Galaxy Phones, and the One UI/Android operating system.

Do you like this post? Kindly, let us know on X/Twitter: we love hearing your feedback! If you prefer using other social platforms besides X, follow/join us on Google News, Facebook, and Telegram.

Continue Reading