SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23790

MEDIUM · CVSS 4.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A double-free vulnerability in the Samsung Exynos DPU driver affects multiple mobile processor models, resulting from improper pointer management during DMA buffer reallocation. This flaw can lead to kernel memory corruption and potential use-after-free conditions, which may allow attackers to execute arbitrary code or escalate privileges. Device manufacturers and security teams managing affected Exynos processors should prioritize patching this vulnerability to mitigate risks associated with exploitation.

CVE
CVE-2026-23790
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%

Original NVD Description

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.