Carrier locked RE: Note20 ABL Odin out-of-bounds read (DoS)
A pre-authentication out-of-bounds write vulnerability exists in the bootloader Odin/LOKE decompressor of certain Snapdragon SM8250 Samsung Galaxy devices, including the Note20 (SM-N986U) US variant. This flaw allows an attacker to cause a recoverable denial of service (DoS) by corrupting UEFI memory, leading to device reboot out of Download Mode. The issue affects end-of-life US Snapdragon models and has been patched in supported devices such as the S20 FE and all S21 through S25 models. Exynos variants are not affected due to different bootloaders.
AI Analysis
Technical Summary
The vulnerability is a pre-authentication out-of-bounds write in the decompression routine of the Odin/LOKE download-mode image in the bootloader of Snapdragon SM8250-based Samsung Galaxy devices (Note20 SM-N986U, S20/+/Ultra SM-G98xU, Z Fold2 SM-F916U, Z Flip 5G SM-F707U). An attacker-controlled copy length exceeds the decompression staging buffer before signature verification, corrupting live UEFI memory, specifically the Graphics Output Protocol. This corruption causes the device to reboot out of Download Mode with a visible error message. The flaw results in a recoverable denial of service without code execution or persistent storage modification. It affects US Snapdragon SKUs on their final firmware, all end-of-life, and has been fixed in supported devices. Exynos variants are unaffected due to different bootloader implementations.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by triggering an out-of-bounds write in the bootloader decompression process. This leads to corruption of UEFI memory and forces the device to reboot out of Download Mode. There is no code execution or permanent data corruption, and the DoS is recoverable. The impact is limited to device availability during the attack window and requires physical or logical access to Download Mode.
Mitigation Recommendations
The vulnerability has been patched in supported Samsung devices including the S20 FE and all S21 through S25 models. End-of-life affected devices (US Snapdragon SKUs) remain vulnerable on their final firmware. Users should update to supported patched firmware if possible. Since this is a bootloader-level issue affecting end-of-life devices, no official fix is available for those models. Avoid placing vulnerable devices in Download Mode when untrusted parties have access. No further mitigation is indicated by the vendor research.
Carrier locked RE: Note20 ABL Odin out-of-bounds read (DoS)
Description
A pre-authentication out-of-bounds write vulnerability exists in the bootloader Odin/LOKE decompressor of certain Snapdragon SM8250 Samsung Galaxy devices, including the Note20 (SM-N986U) US variant. This flaw allows an attacker to cause a recoverable denial of service (DoS) by corrupting UEFI memory, leading to device reboot out of Download Mode. The issue affects end-of-life US Snapdragon models and has been patched in supported devices such as the S20 FE and all S21 through S25 models. Exynos variants are not affected due to different bootloaders.
Reddit Discussion
Trying to figure out a way to get root access to a US Note 20 ultra 5g. I made some progress but hit a wall. https://github.com/UnsignedChad/galaxy-note20-abl-odin-re
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability is a pre-authentication out-of-bounds write in the decompression routine of the Odin/LOKE download-mode image in the bootloader of Snapdragon SM8250-based Samsung Galaxy devices (Note20 SM-N986U, S20/+/Ultra SM-G98xU, Z Fold2 SM-F916U, Z Flip 5G SM-F707U). An attacker-controlled copy length exceeds the decompression staging buffer before signature verification, corrupting live UEFI memory, specifically the Graphics Output Protocol. This corruption causes the device to reboot out of Download Mode with a visible error message. The flaw results in a recoverable denial of service without code execution or persistent storage modification. It affects US Snapdragon SKUs on their final firmware, all end-of-life, and has been fixed in supported devices. Exynos variants are unaffected due to different bootloader implementations.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by triggering an out-of-bounds write in the bootloader decompression process. This leads to corruption of UEFI memory and forces the device to reboot out of Download Mode. There is no code execution or permanent data corruption, and the DoS is recoverable. The impact is limited to device availability during the attack window and requires physical or logical access to Download Mode.
Mitigation Recommendations
The vulnerability has been patched in supported Samsung devices including the S20 FE and all S21 through S25 models. End-of-life affected devices (US Snapdragon SKUs) remain vulnerable on their final firmware. Users should update to supported patched firmware if possible. Since this is a bootloader-level issue affecting end-of-life devices, no official fix is available for those models. Avoid placing vulnerable devices in Download Mode when untrusted parties have access. No further mitigation is indicated by the vendor research.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a380218eed863c81ef9186e
Added to database: 06/21/2026, 15:24:08 UTC
Last enriched: 06/21/2026, 15:24:12 UTC
Last updated: 06/22/2026, 04:09:11 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.