Integer Overflow to Buffer Overflow in Samsung Open Source rlottie
CVE-2026-19588

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-19588?

The rlottie library by Samsung is susceptible to an integer overflow that can lead to buffer overflow vulnerabilities. This flaw allows attackers to manipulate memory allocation, potentially leading to unexpected behaviors, crashes, or exploitation of the system. Proper handling of user inputs and rigorous bounds checking during memory allocation are recommended to mitigate the risks associated with this vulnerability.

Affected Version(s)

rlottie 8117b9ee595763f35c0da2c07181203959f0c510

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.