Out-of-Bounds Write Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23791

4.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-23791?

A significant security concern has been identified in the DPU of Samsung's Exynos mobile processors, specifically affecting models 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. The vulnerability is an out-of-bounds write in the DPU driver, stemming from insufficient validation of input lengths during color mode LUT parsing. This flaw can lead to kernel memory corruption, potentially allowing an attacker to escalate privileges, thereby compromising the integrity of the affected device's operating system.

Affected Version(s)

Exynos 1280 firmware 0 <= 2025-12-29

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.