CVE-2026-23791 PUBLISHED

Assigner: mitre
Reserved: 16.01.2026 Published: 14.09.2026 Updated: 14.09.2026

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
CVSS Score: 4.2

Product Status

Vendor Samsung
Product Exynos 1280 firmware
Versions Default: unknown
  • affected from 0 to 2025-12-29 (incl.)

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE