Buffer Overflow in Samsung Open Source ONE Affecting Memory Handling
CVE-2026-40449

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-40449?

An integer overflow vulnerability exists in Samsung Open Source ONE during the buffer size calculation process. This flaw may allow for out-of-bounds memory access when managing large tensors, which could lead to unexpected behaviors or crashes. Users are encouraged to update to version 1.30.0 or later to mitigate this issue. The vulnerability underscores the importance of rigorous memory management and safe coding practices in software development.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.