CVE-2026-33963
Received Received - Intake

Stack-Based Buffer Overflow in Samsung Mobile Processor Camera Driver

Vulnerability report for CVE-2026-33963, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
samsung exynos 1330
samsung exynos 1380
samsung exynos 1480
samsung exynos 2400
samsung exynos 1580
samsung exynos 2500
samsung exynos 2600
samsung exynos 1680

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in the camera driver of Samsung Exynos processors. It occurs when a malformed message is sent to the camera driver, causing memory handling instability that may lead to a denial of service.

Detection Guidance

Detection of this vulnerability requires checking for stack-based buffer overflows in the camera driver of affected Samsung Exynos processors. Monitor system logs for camera driver crashes or memory corruption errors. Check for unusual camera behavior or application crashes after processing image data.

Impact Analysis

The vulnerability could allow an attacker to cause a denial of service on affected devices by sending a malformed message to the camera driver. This may disrupt camera functionality or other services relying on the camera subsystem.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability involves a stack-based buffer overflow in Samsung Exynos processors' camera driver, which could lead to denial of service. Compliance implications would depend on how the affected devices are used in systems handling regulated data.

Mitigation Strategies

Apply the latest security patches from Samsung for the affected Exynos processors. Check Samsung's official support page for updates and install them immediately to prevent potential denial of service via malformed camera messages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33963. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart