Impact
An improperly controlled sequential memory allocation flaw in Samsung’s open‑source rlottie library allows exponential data expansion when processing oversized serialized payloads. This vulnerability, classified as CWE‑1325, can consume excessive memory and cause the program to crash, leading to a denial of service for applications that rely on rlottie to render animations. The impact is limited to availability and does not expose sensitive data directly.
Affected Systems
The affected product is Samsung Open Source rlottie. No specific version information is provided in the CNA data, so all releases prior to the pending fix should be considered vulnerable if they contain the same unvalidated input handling.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying that there is no confirmed exploitation at the time of this analysis. The likely attack vector would involve providing a crafted serialized payload to the rlottie component; such an exploit could be local or remote depending on how the library is exposed by the application. Overall, the risk is moderate but could be heightened in systems that accept unchecked data from untrusted sources.
OpenCVE Enrichment