Impact
An out‑of‑bounds write in the Exynos DPU driver is caused by missing input length validation during color mode LUT parsing. This flaw overwrites kernel memory, giving an attacker the ability to execute arbitrary code at elevated privileges, as identified by CWE‑787. The resulting kernel corruption can compromise confidentiality, integrity, and availability of the device and all services running on it.
Affected Systems
Samsung’s Exynos processor families—including the 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600 variants—are affected when running the Exynos 1280 firmware. The advisory does not list specific firmware versions, so users should verify the build against Samsung’s product security update repository.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity, while the EPSS score of < 1% shows a very low but non‑zero likelihood of real‑world exploitation. The vulnerability is not catalogued in CISA KEV. The available attack vector likely requires an attacker to craft malformed LUT data that reaches the DPU driver, which would typically demand local or privileged access to the device’s GPU subsystem. In the absence of public exploitation evidence, the risk remains moderate but should not be ignored by systems that expose the DPU driver to untrusted input.
OpenCVE Enrichment