Description
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
Published: 2026-08-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw is a stack-based buffer overflow located in the Samsung Mobile Device library component libril_sem.so. Because the vulnerability exists in a privileged system library, an attacker with local device access and sufficient privileges can potentially execute arbitrary code. The flaw directly jeopardizes confidentiality, integrity, and availability of the affected mobile devices by allowing privileged attackers to take complete control of the system.

Affected Systems

All Samsung Mobile Devices that are running firmware prior to the SMR Aug‑2026 Release 1 update are affected. The specific versions impacted are those before the release of the August 2026 security update, which contains the fix for the libril_sem.so buffer overflow.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. Although the EPSS score is not available, the lack of a listing in the CISA KEV catalog suggests that no publicly documented exploits are known at this time. The likely attack vector is local privileged, meaning an attacker must already have local access with elevated rights to succeed. Given the high CVSS, even in the absence of widespread exploitation, the vulnerability represents a significant risk for affected devices.

Generated by OpenCVE AI on August 10, 2026 at 09:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to SMR Aug‑2026 Release 1 or later, which replaces the vulnerable libril_sem.so binary with a corrected version.
  • If a firmware upgrade is unavailable, restrict local privileged access and isolate the device from trusted networks to mitigate the risk until a patch can be applied.
  • Enable device encryption to protect data in case of privilege escalation, ensuring that sensitive information remains protected even if the device is compromised.

Generated by OpenCVE AI on August 10, 2026 at 09:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Samsung Mobile Device libril_sem.so
Weaknesses CWE-121

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:41:01.485Z

Reserved: 2025-12-11T01:33:35.823Z

Link: CVE-2026-21068

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow