Integer Overflow in Samsung Open Source ONE Leading to Out of Bounds Access
CVE-2026-41666

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41666?

An integer overflow vulnerability exists in the tensor copy size calculation within Samsung Open Source ONE. This could result in out of bounds access during loop state propagation, potentially allowing unauthorized actions or data manipulation. Affected versions include those prior to commit 1.30.0, making timely updates critical to maintaining the integrity and security of applications utilizing this framework.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.