Description
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Published: 2026-08-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in libcodec2_sec_flacdec.so allows local attackers to write out‑of‑bounds memory by crafting malicious FLAC files. This flaw can corrupt process memory, potentially leading to crashes, denial of service, or unintended behavior within the media playback subsystem.

Affected Systems

Samsung Mobile Devices running firmware versions prior to SMR Aug‑2026 Release 1 are affected. No specific firmware revision numbers are listed, so all devices operating the vulnerable library version are considered at risk.

Risk and Exploitability

The CVSS score of 5.1 indicates medium severity, and the lack of an EPSS score means current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, and it requires local access with the ability to supply a malicious FLAC file. While it does not provide remote access, a successful out‑of‑bounds write could lead to memory corruption and potential privilege escalation on the device if the exploited process has elevated permissions.

Generated by OpenCVE AI on August 10, 2026 at 09:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Samsung firmware update (SMR Aug‑2026 Release 1) that replaces the vulnerable libcodec2_sec_flacdec.so.
  • If the firmware update cannot be applied immediately, restrict the playback of untrusted FLAC files by disabling third‑party media players or configuring the existing player to run in a sandboxed environment.
  • Watch for abnormal application crashes or instability after media playback and notify Samsung support while awaiting the official patch.

Generated by OpenCVE AI on August 10, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Samsung FLAC Decoder (libcodec2_sec_flacdec.so)
Weaknesses CWE-20
CWE-787

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:41:02.402Z

Reserved: 2025-12-11T01:33:35.823Z

Link: CVE-2026-21066

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses