Out of Bounds Access in Samsung Open Source ONE Due to Improper String Metadata Validation
CVE-2026-6839

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-6839?

The vulnerability arises from improper validation of STRING tensor offsets within Samsung Open Source ONE, which can result in out-of-bounds access during constant tensor import. This security flaw manifests when malformed string metadata is processed, potentially leading to unexpected behavior or exploitation. Systems utilizing affected versions prior to commit 1.30.0 may be at risk and should prioritize updates to mitigate this vulnerability.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.