Double-Free Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23790

4.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-23790?

A double-free vulnerability has been identified in the DPU driver of Samsung's Exynos mobile processors. This flaw occurs due to improper pointer management during the reallocation of DMA buffers, which can lead to kernel memory corruption and a potential use-after-free scenario. Exploitation of this vulnerability can compromise system integrity, making it critical for users of affected Exynos processors to apply the recommended patches and updates to mitigate potential security risks.

Affected Version(s)

Exynos 1280 firmware 0 <= 2025-12-29

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.