SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23791

MEDIUM · CVSS 4.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An out-of-bounds write vulnerability in the DPU driver of several Samsung Mobile Processors, including the Exynos 1280 and 2200 series, allows for kernel memory corruption due to inadequate input length validation during color mode LUT parsing. This could lead to potential privilege escalation, impacting the integrity and security of affected devices. Organizations using these processors should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-23791
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%

Original NVD Description

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.