Integer Overflow Vulnerability in Samsung Open Source ONE Product
CVE-2026-41667

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41667?

An integer overflow vulnerability exists in Samsung Open Source ONE, affecting the calculation of constant tensor data sizes. This flaw can lead to incorrect buffer sizing for large constant nodes, potentially resulting in unexpected behavior or crashes. Users are encouraged to update to version 1.30.0 or later to mitigate these issues. More details can be found in the official GitHub pull request.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.