Out-of-Bounds Write Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23791
4.2MEDIUM
What is CVE-2026-23791?
A significant security concern has been identified in the DPU of Samsung's Exynos mobile processors, specifically affecting models 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. The vulnerability is an out-of-bounds write in the DPU driver, stemming from insufficient validation of input lengths during color mode LUT parsing. This flaw can lead to kernel memory corruption, potentially allowing an attacker to escalate privileges, thereby compromising the integrity of the affected device's operating system.
Affected Version(s)
Exynos 1280 firmware 0 <= 2025-12-29