Wednesday, December 4, 2024

Samsung month-to-month updates: December 2024 safety patch detailed

Final up to date: December third, 2024 at 13:23 UTC+01:00

So far as we are able to inform, no Galaxy system has but obtained the December 2024 safety patch. Nevertheless, Samsung seems to be gearing up for the occasion, because it lately confirmed the December replace’s changelog by means of its month-to-month safety bulletin.

As normal, Samsung’s newest launch contains safety fixes from each Google and Samsung. And this month, the replace additionally contains a few fixes from Samsung Semiconductor.

On Google’s aspect, the December 2024 safety replace accommodates fixes for important and excessive vulnerabilities, however none for moderate-level ones.

Vital

  • CVE-2024-38408, CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747, CVE-2024-49748

Excessive

  • CVE-2024-34747, CVE-2024-40671, CVE-2024-34729, CVE-2024-31337, CVE-2023-35659, CVE-2023-35686, CVE-2024-23715, CVE-2024-36978, CVE-2024-46740, CVE-2024-20106, CVE-2024-20104, CVE-2024-23385, CVE-2024-38403, CVE-2024-38424, CVE-2024-38415, CVE-2024-38423, CVE-2024-38421, CVE-2024-21455, CVE-2024-43047, CVE-2024-38405, CVE-2024-43762, CVE-2024-43764, CVE-2024-43769, CVE-2024-43767, CVE-2024-43097, CVE-2024-43768, CVE-2024-43766, CVE-2024-43763

Already included in earlier updates

On Samsung Cell’s aspect of the equation, the December 2024 safety patch contains 8 SVE (Samsung Vulnerabilities and Exposures) objects, solely six of which have been disclosed:

  • SVE-2024-1485(CVE-2024-49410): Out-of-bounds write in libswmfextractor.so
  • SVE-2024-1808(CVE-2024-49411): Path Traversal in ThemeCenter
  • SVE-2024-1845(CVE-2024-49415): Out-of-bound write in libsaped.so
  • SVE-2024-1885(CVE-2024-49412): Improper enter validation in Settings
  • SVE-2024-2044(CVE-2024-49413): Improper Verification of Cryptographic Signature in SmartSwitch
  • SVE-2024-2166(CVE-2024-49414): Authentication Bypass Utilizing an Alternate Path in Dex Mode

Final however not least, as we talked about above, the December 2024 safety patch additionally contains two vulnerability fixes from Samsung Semiconductor. They’re labeled a high-security danger and are referred to as

  • CVE-2024-39343
  • CVE-2024-39890

Samsung hasn’t launched the December 2024 safety patch to any Galaxy telephones or tablets as of this writing, however it’s going to seemingly begin the OTA roll-out quickly. We’ll preserve you posted as soon as it does.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles