Learn about CVE-2018-21058 affecting Samsung mobile devices running N(7.0) and O(8.0) software with Exynos7420 or Exynos 8890/8996 chipsets. Find out the impact, affected systems, exploitation mechanism, and mitigation steps.
A vulnerability has been identified on Samsung mobile devices running N(7.0) and O(8.0) software with Exynos7420 or Exynos 8890/8996 chipsets, exposing the Keymaster AES-GCM implementation to cache attacks.
Understanding CVE-2018-21058
This CVE refers to a security issue affecting Samsung mobile devices with specific software versions and chipsets.
What is CVE-2018-21058?
The vulnerability in CVE-2018-21058 allows cache attacks on the Keymaster AES-GCM implementation due to the absence of Cryptography Extension (CE) and the use of T-Tables.
The Impact of CVE-2018-21058
The vulnerability poses a security risk to the confidentiality and integrity of data stored on affected Samsung mobile devices.
Technical Details of CVE-2018-21058
This section provides more technical insights into the vulnerability.
Vulnerability Description
The vulnerability arises from the use of T-Tables and the absence of Cryptography Extension (CE) in the Keymaster AES-GCM implementation on Samsung devices.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability allows attackers to launch cache attacks against the Keymaster AES-GCM implementation, potentially compromising sensitive data.
Mitigation and Prevention
Protecting devices from CVE-2018-21058 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates