Description
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
Published: 2026-09-14
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential use‑after‑free
Action: Apply Vendor Patch
AI Analysis

Impact

The flaw is a double‑free in the Samsung Exynos DPU driver caused by improper pointer handling during DMA buffer reallocations, which can corrupt kernel memory and potentially lead to a use‑after‑free scenario. An attacker that can trigger the reallocation path could overwrite critical kernel data structures, creating a window for privilege escalation or denial of service. The weakness is classified as CWE‑415 and is tied to kernel memory integrity.

Affected Systems

The vulnerability affects Samsung mobile processors that ship with Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600 firmware. All firmware releases containing the unpatched DPU driver are impacted. Devices running these chipsets with the current firmware are at risk.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity. The EPSS score is less than 1% (0.00091), suggesting a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, implying no known widespread exploitation yet. The likely attack vector involves an attacker capable of interacting with the DMA engine, such as a privileged local process or a component driving the DPU, to trigger the double‑free. Because it requires kernel interaction, exploitation is constrained to local or privileged contexts, but the kernel memory corruption could provide a foothold for further privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 15:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Freeze to the latest firmware update from Samsung that contains the DPU driver patch.
  • If firmware cannot be updated immediately, isolate the affected DMA resources or disable the DPU function through kernel configuration or BIOS settings, reducing the attack surface.
  • As a temporary measure, apply any available community‑issued kernel patch that reintroduces safe to test in a staging environment before production.

Generated by OpenCVE AI on September 15, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Double-Free in Exynos DPU Driver Causes Kernel Memory Corruption

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Double-Free Vulnerability in Samsung Exynos DPU Driver Leading to Kernel Memory Corruption

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Double-Free Vulnerability in Samsung Exynos DPU Driver Leading to Kernel Memory Corruption

Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
First Time appeared Samsung
Samsung exynos 1280 Firmware
Weaknesses CWE-415
CPEs cpe:2.3:a:samsung:exynos_1280_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1280 Firmware
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Subscriptions

Samsung Exynos 1280 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:00:39.431Z

Reserved: 2026-01-16T00:00:00.000Z

Link: CVE-2026-23790

cve-icon Vulnrichment

Updated: 2026-09-14T16:00:36.293Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T02:17:13.537

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-23790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:00:17Z

Weaknesses