Description
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks.

This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
Published: 2026-06-04
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw exists in the Samsung Open Source rlottie library that allows attackers to perform integer attacks. This weakness can lead to erroneous calculations during animation rendering, which may result in incorrect memory allocation, buffer overrun or other anomalous behavior that can compromise application integrity or availability. The vulnerability is designated as a classic integer error (CWE-190).

Affected Systems

The flaw is present in all releases of Samsung Open Source rlottie before commit 21292665023e5074b38254432716866d00f1985f. Any product or application that incorporates an older version of this library, including downstream consumer applications or custom software, supplies the vulnerable component. Specific downstream users are not listed beyond the main project, but any reuse of this open‑source component in custom or commercial code is at risk.

Risk and Exploitability

The CVSS score of 6.1 classifies this as a medium‑severity issue. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation campaigns. Exploitation would likely involve supplying a maliciously crafted Lottie file to an application that parses it with the vulnerable library. Because the flaw manifests during integer arithmetic in parsing, an attacker with access to such input could potentially cause a denial of service or, depending on memory handling, facilitate further exploitation. The primary attack vector is application‑level input, and the vulnerability requires the target to load a manipulated animation file.

Generated by OpenCVE AI on June 4, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update rlottie to a version that includes commit 21292665023e5074b38254432716866d00f1985f or newer.
  • Rebuild any applications that depend on rlottie using the updated library and re‑test for functional regression.
  • Monitor application logs for anomalous integer operations or crashes that may indicate exploitation attempts.

Generated by OpenCVE AI on June 4, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in rlottie Enables Malicious Animation Parsing

Thu, 04 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-06-04T09:41:17.647Z

Reserved: 2026-06-01T01:41:22.546Z

Link: CVE-2026-49510

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T10:16:39.457

Modified: 2026-06-04T10:16:39.457

Link: CVE-2026-49510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T12:30:13Z

Weaknesses