Description
Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local memory corruption
Action: Apply patch
AI Analysis

Impact

An out-of-bounds write in the Samsung libsthmbc.so library allows local attackers to corrupt memory. The vulnerability arises when the library writes beyond its buffer boundaries, potentially overwriting critical data structures and enabling further exploitation. This type of flaw is commonly referred to as a buffer overflow weakness.

Affected Systems

Samsung Mobile devices that incorporate the libsthmbc component and run a version of One UI before 8.5. The specific affected firmware or build versions are not enumerated in the advisory, but the risk applies to any device using the vulnerable library on these older OS releases.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating moderate severity, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is unavailable, but the lack of KEV listing suggests no widespread exploitation in the public domain. The attack requires local access to the device, meaning physical possession or a local malicious application would be needed to trigger the overflow.

Generated by OpenCVE AI on September 9, 2026 at 10:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Samsung One UI firmware update (8.5 or later) that contains the libsthmbc fix.
  • Enable automatic software updates so subsequent patches are applied without delay.
  • If an update cannot be applied immediately, restrict physical access to the device, disable USB debugging, and monitor for any suspicious local activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 9, 2026 at 10:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile libsthmbc
Vendors & Products Samsung Mobile
Samsung Mobile libsthmbc

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung libsthmbc Allows Local Memory Corruption
Weaknesses CWE-119
CWE-787

Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Libsthmbc
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-09-10T14:11:03.793Z

Reserved: 2025-12-11T01:33:35.830Z

Link: CVE-2026-21111

cve-icon Vulnrichment

Updated: 2026-09-10T14:10:49.022Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T05:17:23.640

Modified: 2026-09-10T15:17:29.100

Link: CVE-2026-21111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write