Description
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
Published: 2026-08-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow flaw in the Samsung rlottie library can cause a buffer overflow, leading to potential memory corruption and remote code execution if an attacker can supply malicious animation data. The description does not specify the exact exploitation scenario, but the presence of a buffer overflow suggests that corrupted memory could be leveraged to alter program flow.

Affected Systems

Samsung’s open‑source rlottie animation rendering library. Any software incorporating this library, particularly those that accept external animation files, is potentially impacted. The vendor list is limited to the rlottie project; no specific versions are supplied in the data.

Risk and Exploitability

The CVSS score of 6.5 reflects moderate severity, while the EPSS score of less than 1 percent indicates a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or contextual: an attacker would need to deliver crafted animation data to a process that loads rlottie. Without further detail, it is inferred that exploitation would require either a privileged or user‑controlled context within the application using the library.

Generated by OpenCVE AI on August 12, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade rlottie to the latest stable release that contains the integer‑to‑buffer‑overflow fix.
  • If an upgrade is not immediately possible, remove or disable the rlottie component in the affected application to eliminate the risk.
  • Implement runtime monitoring for abnormal memory allocation failures and log buffer overrun attempts to detect potential exploitation.

Generated by OpenCVE AI on August 12, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in rlottie Leading to Buffer Overflow

Wed, 12 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
Weaknesses CWE-680
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-08-12T13:33:37.037Z

Reserved: 2026-08-12T02:18:18.508Z

Link: CVE-2026-19588

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T03:16:43.083

Modified: 2026-08-12T14:17:49.540

Link: CVE-2026-19588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T14:30:03Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow