Description
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Published: 2026-08-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in the VC1 codec library (libsavsvc.so) allows a local attacker to overwrite memory beyond the bounds of a buffer. The overwrite can corrupt data structures in the codec process, potentially enabling privilege escalation or causing a denial of service. The weakness is a classic bounds‑checking failure, corresponding to CWE‑119. The impact is therefore memory corruption confined to the process that decodes VC1 streams, but with the possibility of escalating privileges if the codec runs with higher privileges.

Affected Systems

The flaw exists in Samsung Mobile Devices that run firmware versions older than the SMR Aug‑2026 Release 1 update. Any device whose media framework bundles the vulnerable libsavsvc.so library is affected.

Risk and Exploitability

The CVSS score of 5.1 characterizes the vulnerability as moderate. No EPSS data is available, and it is not listed in the CISA KEV catalog. Because an attacker must be able to locally feed a crafted VC1 stream to the device, exploitation requires physical or otherwise local access to the device. If achieved, the out‑of‑bounds write could destabilize the codec process or allow privilege escalation, but remote exploitation is not supported by the current data.

Generated by OpenCVE AI on August 10, 2026 at 09:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Samsung for a firmware update that includes a fix for the VC1 codec library.
  • If no update is available, disable or remove the VC1 codec by preventing the associated library from loading or executing.
  • Monitor the device for crashes, illegal memory accesses, or abnormal behavior and enforce restrictive physical access controls.

Generated by OpenCVE AI on August 10, 2026 at 09:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via VC1 Codec in Samsung Mobile Devices
Weaknesses CWE-119

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:42:09.325Z

Reserved: 2025-12-11T01:33:35.824Z

Link: CVE-2026-21072

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T11:00:11Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer