Description
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
Published: 2026-09-14
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption and system crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a heap overflow in the Exynos DRM HDR driver caused by improper buffer size validation, which leads to kernel memory corruption and crashing the system. The flaw falls under CWE-122 (Heap Buffer Overflow) and can cause a denial of service via kernel panic.

Affected Systems

Affected vendors include Samsung, with the flaw present in the Exynos 1280 firmware (and the description also mentions the 2200 and 1380 lines). The vulnerability exists in the firmware that ships with these mobile processors; specific affected firmware versions are not listed in the advisory, so any device running the default firmware before the vendor’s update may be impacted.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity, and the EPSS score of less than 1% along with its absence from the KEV catalog suggests it is not widely exploited yet. The attack vector is inferred to be local or requires privileged access to invoke DRM HDR operations, since the overflow occurs within a kernel module. Until an update is applied, devices could experience repeated crashes if the vulnerable interface is used.

Generated by OpenCVE AI on September 15, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version supplied by Samsung’s product-security updates, which includes the fixed DRM HDR driver.
  • Restart the device after the firmware update to ensure the corrected kernel module is loaded.
  • If the device does not auto-update, disable or restrict use of DRM HDR features until the patched firmware is installed.

Generated by OpenCVE AI on September 15, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Exynos DRM HDR Driver Heap Overflow Leading to System Crash

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Exynos DRM HDR Driver Heap Overflow Causing Kernel Corruption

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Exynos DRM HDR Driver Heap Overflow Causing Kernel Corruption

Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
First Time appeared Samsung
Samsung exynos 1280 Firmware
Weaknesses CWE-122
CPEs cpe:2.3:a:samsung:exynos_1280_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1280 Firmware
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Subscriptions

Samsung Exynos 1280 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:11:47.015Z

Reserved: 2026-01-16T00:00:00.000Z

Link: CVE-2026-23788

cve-icon Vulnrichment

Updated: 2026-09-14T15:11:42.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T02:17:13.267

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-23788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:00:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow