Double-Free Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23790
4.2MEDIUM
What is CVE-2026-23790?
A double-free vulnerability has been identified in the DPU driver of Samsung's Exynos mobile processors. This flaw occurs due to improper pointer management during the reallocation of DMA buffers, which can lead to kernel memory corruption and a potential use-after-free scenario. Exploitation of this vulnerability can compromise system integrity, making it critical for users of affected Exynos processors to apply the recommended patches and updates to mitigate potential security risks.
Affected Version(s)
Exynos 1280 firmware 0 <= 2025-12-29