Description
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write flaw exists in Samsung’s libsavsac.so library that precedes the July 2026 Release 1 security update. The vulnerability allows a local attacker—someone with physical access or the ability to run privileged code—to write data past the end of a buffer in the library, thereby enabling execution of arbitrary code in the device’s context. The flaw satisfies CWE‑119 and CWE‑787, and an attacker could compromise the confidentiality, integrity, and availability of the affected device.

Affected Systems

Samsung Mobile Devices, including all models running the pre‑July 2026 Release 1 version of libsavsac.so, are affected. The advisory does not specify particular firmware levels, so any device with the unpatched library is at risk until the update is applied.

Risk and Exploitability

The CVSS score (8.4) denotes high severity; however, the EPSS (< 1%) indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers must acquire local access—such as physical possession of the device or the capability to run privileged code—to trigger the out-of-bounds write and achieve arbitrary code execution.

Generated by OpenCVE AI on July 28, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the July 2026 security update from Samsung that contains the libsavsac.so fix.
  • Ensure that only trusted applications have permission to load or interact with libsavsac.so by reviewing app sandboxing and privilege levels.
  • Monitor system logs for unexpected memory errors or crashes that could indicate exploitation attempts.

Generated by OpenCVE AI on July 28, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Buffer Write in libsavsac.so Enabling Local Arbitrary Code Execution

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Arbitrary Code Execution via Out-of-Bounds Write in libsavsac.so
Weaknesses CWE-119
CWE-787

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Arbitrary Code Execution via Out-of-Bounds Write in libsavsac.so
Weaknesses CWE-119
CWE-787

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in libsavsac.so enables local code execution on Samsung Mobile Devices

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in libsavsac.so enables local code execution on Samsung Mobile Devices
Weaknesses CWE-119
CWE-787

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in libsavsac.so Enables Local Arbitrary Code Execution
Weaknesses CWE-119
CWE-787

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in libsavsac.so Enables Local Arbitrary Code Execution

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung libsavsac.so Allows Local Arbitrary Code Execution
Weaknesses CWE-119
CWE-787

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung libsavsac.so Allows Local Arbitrary Code Execution
Weaknesses CWE-119
CWE-787

Sat, 11 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Local Out‑of‑Bounds Write in Samsung libsavsac.so Leading to Arbitrary Code Execution
Weaknesses CWE-787

Fri, 10 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Out‑of‑Bounds Write in Samsung libsavsac.so Leading to Arbitrary Code Execution
Weaknesses CWE-787

Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-11T03:55:21.047Z

Reserved: 2025-12-11T01:33:35.815Z

Link: CVE-2026-21042

cve-icon Vulnrichment

Updated: 2026-07-10T12:26:54.576Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses

No weakness.