Integer Overflow Vulnerability in Samsung Open Source ONE
CVE-2026-41665

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41665?

An integer overflow vulnerability exists in the initialization size calculation of the scratch buffer within Samsung Open Source ONE. This flaw can lead to improper memory initialization, particularly affecting large intermediate tensors. As a result, applications utilizing this software version might encounter unpredictable behavior or potential security risks. Users are advised to upgrade to versions after commit 1.30.0 to mitigate this vulnerability.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.