Description
Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung's libimagecodec.media.quram.so parses DNG image files and contains a flaw that triggers an out-of-bounds write when handling malformed input. A crafted malicious DNG file can be processed by the library, overwriting adjacent memory and corrupting data or control flow. The vulnerability may cause application crashes or, if key control structures are affected, could lead to more severe consequences such as privilege escalation for the app.

Affected Systems

Any Samsung mobile device that uses libimagecodec.media.quram.so before the July 2026 SMR Release 1 is impacted. No specific device models or OS revisions are listed, so users of all devices that include the unpatched library version are at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The flaw is remote: a malicious DNG file can be delivered via email, messaging, or other file transfer methods. If the file is opened or imported, the out-of-bounds write may corrupt memory, presenting a realistic risk of arbitrary memory corruption.

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Samsung’s latest security update that patches libimagecodec.media.quram.so
  • Until the patch is applied, avoid opening or importing DNG files from untrusted sources; consider disabling photo import features in messaging or email applications
  • Monitor devices for abnormal application crashes or instability after image imports and report any incidents to Samsung support

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write via Malformed DNG in Samsung Image Codec
Weaknesses CWE-787

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung Image Codec During DNG Parsing
Weaknesses CWE-122
CWE-788

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung Image Codec During DNG Parsing
Weaknesses CWE-122
CWE-788

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung DNG Image Parser
Weaknesses CWE-787

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung DNG Image Parser
Weaknesses CWE-787

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds Write in Samsung DNG Parsing
Weaknesses CWE-787

Sat, 11 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds Write in Samsung DNG Parsing
Weaknesses CWE-787

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T15:05:58.428Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21048

cve-icon Vulnrichment

Updated: 2026-07-10T15:05:43.861Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses