CVE-2026-23790
Received Received - Intake

Double-Free in Samsung Exynos DPU Driver

Vulnerability report for CVE-2026-23790, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
samsung exynos_dpu *
samsung exynos_1280 *
samsung exynos_2200 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_2400 *
samsung exynos_1580 *
samsung exynos_2500 *
samsung exynos_1680 *
samsung exynos_2600 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-23790 is a double-free vulnerability in the Samsung Exynos DPU driver. It occurs due to improper pointer management during DMA buffer reallocation, leading to kernel memory corruption and potential use-after-free conditions.

Detection Guidance

Detection requires checking for affected Samsung Exynos DPU drivers on devices using Exynos chipsets. Use system commands like 'uname -a' to identify kernel version and 'lsmod | grep exynos_dpu' to check loaded DPU modules. Inspect kernel logs for memory corruption errors or use-after-free warnings.

Impact Analysis

This vulnerability may allow attackers to execute arbitrary code, escalate privileges, or cause system crashes. It primarily affects devices using vulnerable Exynos chipsets, potentially compromising system stability and security.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling kernel memory corruption and use-after-free conditions, which may lead to unauthorized data access or system instability. Such conditions could violate data integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Apply security patches from Samsung immediately. Disable the Exynos DPU driver if not essential. Monitor kernel logs for memory corruption or use-after-free events. Restrict access to affected devices and update firmware to the latest version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23790. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart