Description
Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Samsung’s libimagecodec.media.quram.so library, which processes DNG image files. When a malformed DNG file is parsed, the library writes outside the bounds of a memory buffer. This out-of-bounds write can corrupt adjacent memory, potentially causing application crashes or memory corruption. The description does not indicate additional capabilities such as privilege escalation; the impact is limited to memory corruption.

Affected Systems

The flaw affects any Samsung mobile device that includes the unpatched libimagecodec.media.quram.so prior to the SMR Jul‑2026 Release 1 update. No device models or OS versions are specifically listed, so all devices that incorporate the affected library before the update are at risk.

Risk and Exploitability

The CVSS score of 8.4 classifies the issue as high severity. The EPSS score is below 1 %, indicating a low likelihood of exploitation at the time of assessment. The vulnerability is not present in the CISA KEV catalog. It is inferred that an attacker could supply a malicious DNG file to the vulnerable library via any medium that delivers files to the device, such as email attachments or messaging apps. However, the description does not provide explicit details about the exact attack vector, so this inference remains just that—a reasonable assumption based on how image files can be delivered.

Generated by OpenCVE AI on August 5, 2026 at 02:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Samsung’s latest security update that includes a patch for libimagecodec.media.quram.so
  • Until the patch is applied, avoid opening or importing DNG files from untrusted sources; consider disabling photo import features in messaging or email applications
  • Monitor devices for abnormal application crashes or instability after image imports and report any incidents to Samsung support

Generated by OpenCVE AI on August 5, 2026 at 02:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Samsung DNG Parser
Weaknesses CWE-787

Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write via Malformed DNG in Samsung Image Codec
Weaknesses CWE-787

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write via Malformed DNG in Samsung Image Codec
Weaknesses CWE-787

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung Image Codec During DNG Parsing
Weaknesses CWE-122
CWE-788

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung Image Codec During DNG Parsing
Weaknesses CWE-122
CWE-788

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung DNG Image Parser
Weaknesses CWE-787

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung DNG Image Parser
Weaknesses CWE-787

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds Write in Samsung DNG Parsing
Weaknesses CWE-787

Sat, 11 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds Write in Samsung DNG Parsing
Weaknesses CWE-787

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T15:05:58.428Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21048

cve-icon Vulnrichment

Updated: 2026-07-10T15:05:43.861Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:35.410

Modified: 2026-07-10T17:56:00.910

Link: CVE-2026-21048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:45:17Z

Weaknesses