Integer Overflow Vulnerability in Samsung Open Source ONE
CVE-2026-40450

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-40450?

An integer overflow vulnerability exists in the Samsung Open Source ONE framework, where improper calculations during output tensor copy size can lead to incorrect copy length. This may result in memory corruption when processing oversized tensors, potentially allowing for further exploitation and stability issues in applications using the affected versions. Users are advised to update to version 1.30.0 or later to mitigate this risk.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.