Description
Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write in libpadm.so allows a local attacker to overwrite adjacent memory and execute arbitrary code (CWE‑787). It compromises the integrity of the device’s execution environment and requires local access or privileges.

Affected Systems

Samsung Mobile Devices running firmware versions prior to the SMR Jul‑2026 Release 1 that include libpadm.so. No specific device models or OS were disclosed, so any device not updated to the July 2026 SMR is presumed vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity local code execution risk. The EPSS score of less than 1% suggests that exploitation is unlikely to be widely observed at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local, so a threat actor would need physical or local access to the device to exploit this memory corruption flaw.

Generated by OpenCVE AI on July 29, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the SMR Jul-2026 Release firmware update that fixes the out‑of‑bounds write in libpadm.so.
  • If an update is unavailable, restrict physical access to the device and monitor for anomalous activity indicating exploitation.
  • If libpadm.so functionality is nonessential, disable or remove the library to eliminate the vulnerable component.

Generated by OpenCVE AI on July 29, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in libpadm.so allows local code execution on Samsung mobile devices
Weaknesses CWE-787

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in libpadm.so allows local code execution on Samsung mobile devices
Weaknesses CWE-787

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Code Execution via Out-of-Bounds Write in Samsung’s libpadm.so
Weaknesses CWE-787

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Code Execution via Out-of-Bounds Write in Samsung’s libpadm.so
Weaknesses CWE-787

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Samsung libpadm.so Enabling Local Code Execution
Weaknesses CWE-787

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Samsung libpadm.so Enabling Local Code Execution
Weaknesses CWE-787

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in Samsung libpadm.so allows local code execution
Weaknesses CWE-787

Fri, 10 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds write in Samsung libpadm.so allows local code execution
Weaknesses CWE-787

Fri, 10 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-11T03:55:18.770Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21049

cve-icon Vulnrichment

Updated: 2026-07-10T12:18:07.721Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses

No weakness.