Integer Overflow Vulnerability in Samsung Open Source ONE
CVE-2026-40448

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-40448?

An integer overflow vulnerability has been identified in the memory allocation process of Samsung Open Source ONE. This flaw occurs due to improper handling of tensor allocation size calculations, which can result in insufficient memory allocation when dealing with large tensors. Consequently, this could lead to unexpected application behavior or potential crashes. Users are advised to update to version 1.30.0 or later to mitigate this issue.

Affected Version(s)

ONE 95fba2da1880ab3eabc719520e8591c33b65b272

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.