Description
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A stack-based buffer overflow exists in the camera driver of Samsung Exynos processors. When a driver writes past the bounds of an array on the stack, corrupting control data and causing the camera component to crash. The resulting loss of camera functionality constitutes a denial of service for the device. This weakness is a classic buffer overflow (CWE-121).

Affected Systems

The flaw affects Samsung Exynos firmware on the Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680 processor families. All devices running these firmware versions are vulnerable if the camera driver receives a malformed request.

Risk and Exploitability

The CVSS score of 7.5 categorizes the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed that no publicly known exploits exist. The defect is local in scope; attackers would need to deliver a crafted message to the camera driver, likely through a malicious application granted camera access or via local privileged code. Successful exploitation would lead to a local denial of service, disabling camera functionality but not compromising other system components or enabling remote code execution.

Generated by OpenCVE AI on September 15, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Samsung firmware update that includes the camera driver fix
  • Reboot the device to load the updated firmware and ensure the driver is active
  • Restrict camera application permissions to trusted apps to reduce the chance of malformed message delivery
  • Monitor system logs for camera driver crashes and investigate anomalies

Generated by OpenCVE AI on September 15, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Exynos Camera Driver Leads to Denial of Service

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Exynos Camera Driver Leads to Denial of Service

Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
First Time appeared Samsung
Samsung exynos 1330 Firmware
Weaknesses CWE-121
CPEs cpe:2.3:a:samsung:exynos_1330_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1330 Firmware
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Samsung Exynos 1330 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T14:28:45.074Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33963

cve-icon Vulnrichment

Updated: 2026-09-16T14:28:41.169Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T02:17:14.850

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow