Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Carrier locked RE: Note20 ABL Odin out-of-bounds read (DoS)

0
Medium
Security-newscybersecurityreddit
Published: 06/21/2026 (06/21/2026, 14:31:57 UTC)
Source: Reddit Cybersecurity

Description

A pre-authentication out-of-bounds write vulnerability exists in the bootloader Odin/LOKE decompressor of certain Snapdragon SM8250 Samsung Galaxy devices, including the Note20 (SM-N986U) US variant. This flaw allows an attacker to cause a recoverable denial of service (DoS) by corrupting UEFI memory, leading to device reboot out of Download Mode. The issue affects end-of-life US Snapdragon models and has been patched in supported devices such as the S20 FE and all S21 through S25 models. Exynos variants are not affected due to different bootloaders.

Reddit Discussion

r/cybersecurity·posted by u/Greenlinkx
00

Trying to figure out a way to get root access to a US Note 20 ultra 5g. I made some progress but hit a wall. https://github.com/UnsignedChad/galaxy-note20-abl-odin-re

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/21/2026, 15:24:12 UTC

Technical Analysis

The vulnerability is a pre-authentication out-of-bounds write in the decompression routine of the Odin/LOKE download-mode image in the bootloader of Snapdragon SM8250-based Samsung Galaxy devices (Note20 SM-N986U, S20/+/Ultra SM-G98xU, Z Fold2 SM-F916U, Z Flip 5G SM-F707U). An attacker-controlled copy length exceeds the decompression staging buffer before signature verification, corrupting live UEFI memory, specifically the Graphics Output Protocol. This corruption causes the device to reboot out of Download Mode with a visible error message. The flaw results in a recoverable denial of service without code execution or persistent storage modification. It affects US Snapdragon SKUs on their final firmware, all end-of-life, and has been fixed in supported devices. Exynos variants are unaffected due to different bootloader implementations.

Potential Impact

The vulnerability allows an unauthenticated attacker to cause a denial of service by triggering an out-of-bounds write in the bootloader decompression process. This leads to corruption of UEFI memory and forces the device to reboot out of Download Mode. There is no code execution or permanent data corruption, and the DoS is recoverable. The impact is limited to device availability during the attack window and requires physical or logical access to Download Mode.

Mitigation Recommendations

The vulnerability has been patched in supported Samsung devices including the S20 FE and all S21 through S25 models. End-of-life affected devices (US Snapdragon SKUs) remain vulnerable on their final firmware. Users should update to supported patched firmware if possible. Since this is a bootloader-level issue affecting end-of-life devices, no official fix is available for those models. Avoid placing vulnerable devices in Download Mode when untrusted parties have access. No further mitigation is indicated by the vendor research.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a380218eed863c81ef9186e

Added to database: 06/21/2026, 15:24:08 UTC

Last enriched: 06/21/2026, 15:24:12 UTC

Last updated: 06/22/2026, 04:09:11 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses