Description
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
Published: 2026-09-14
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption and system crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a heap overflow in the Exynos DRM HDR driver caused by improper buffer size validation, which leads to kernel memory corruption and crashing the system. The flaw falls under CWE-122 (Heap Buffer Overflow) and can cause a denial of service via kernel panic.

Affected Systems

Affected vendors include Samsung, with the flaw present in the Exynos 1280 firmware (and the description also mentions the 2200 and 1380 lines). The vulnerability exists in the firmware that ships with these mobile processors; specific affected firmware versions are not listed in the advisory, so any device running the default firmware before the vendor’s update may be impacted.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity, and there is no EPSS data or KEV listing, suggesting it is not widely exploited yet. The attack vector is inferred to be local or requires privileged access to invoke DRM HDR operations, since the overflow occurs within a kernel module. Until an update is applied, devices could experience repeated crashes if the vulnerable interface is used.

Generated by OpenCVE AI on September 14, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version supplied by Samsung’s product-security updates, which includes the fixed DRM HDR driver.
  • Restart the device after the firmware update to ensure the corrected kernel module is loaded.
  • If the device does not auto‑update, disable or restrict use of DRM HDR features until the patched firmware is installed.

Generated by OpenCVE AI on September 14, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Exynos DRM HDR Driver Heap Overflow Causing Kernel Corruption

Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
First Time appeared Samsung
Samsung exynos 1280 Firmware
Weaknesses CWE-122
CPEs cpe:2.3:a:samsung:exynos_1280_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1280 Firmware
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Subscriptions

Samsung Exynos 1280 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T00:56:30.800Z

Reserved: 2026-01-16T00:00:00.000Z

Link: CVE-2026-23788

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T02:17:13.267

Modified: 2026-09-14T02:17:13.267

Link: CVE-2026-23788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T12:00:14Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow