Impact
The vulnerability is a resource exhaustion issue that allows an attacker to trigger excessive memory allocation in the rlottie animation rendering library, leading to a denial of service. It is a classic uncontrolled resource consumption flaw (CWE‑1050, CWE‑400). An attacker could cause the application to consume large amounts of heap space, potentially crashing or rendering the service unavailable.
Affected Systems
The affected product is Samsung Open Source:rlottie. No specific version numbers are listed, so any installation of rlottie that has not been updated to the fixed version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through processing a crafted animation file or payload, which may be local or provided via an API that parses user data. Because the flaw arises from uncontrolled allocation, it could be triggered by an attacker who can supply input to rlottie.
OpenCVE Enrichment