CVE-2026-23791
Received Received - Intake

Out-of-Bounds Write in Samsung Exynos DPU Driver

Vulnerability report for CVE-2026-23791, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
samsung exynos_dpu *
samsung exynos_1280 *
samsung exynos_2200 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_2400 *
samsung exynos_1580 *
samsung exynos_2500 *
samsung exynos_1680 *
samsung exynos_2600 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write issue in the Samsung Exynos DPU driver affecting multiple Exynos processors. It occurs due to missing input length validation during color mode LUT parsing, which can corrupt kernel memory and potentially allow privilege escalation.

Impact Analysis

An attacker could exploit this to corrupt kernel memory, leading to system instability or unauthorized privilege escalation. This may allow them to gain elevated access to the device, potentially compromising sensitive data or installing malicious software.

Compliance Impact

The vulnerability involves an out-of-bounds write in the Exynos DPU driver, which could lead to kernel memory corruption and privilege escalation. This type of vulnerability may compromise system integrity, potentially violating data protection requirements under standards like GDPR (data integrity and security) and HIPAA (integrity and availability of protected health information).

Mitigation Strategies

Apply the latest security patches from Samsung for affected Exynos processors. Check for updates via Samsung's official support page or device manufacturer. Disable unnecessary DPU features if patches are unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23791. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart