Heap Overflow Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23786
2.8LOW
What is CVE-2026-23786?
A vulnerability has been identified within the Data Path Unit (DPU) of several Samsung Exynos Mobile Processors, including the Exynos 1280, 2200, and others. This vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) race condition within the Exynos DRM HDR Driver, which can lead to a heap overflow. This overflow has the potential to cause unexpected behavior, including crashes in the kernel, which could compromise the stability of affected devices. Users are advised to monitor updates from Samsung and secure their devices accordingly.
Affected Version(s)
Exynos 1280 firmware 0 <= 2025-12-24