Integer Overflow Vulnerability in Samsung Open Source ONE
CVE-2026-41664

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41664?

An integer overflow issue in the memory copy size calculation within Samsung Open Source ONE could lead to invalid memory operations, particularly when managing large tensor shapes. This may result in unstable behavior or potential application crashes. It is essential to update to version 1.30.0 or later to mitigate these risks.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.