Description
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.

This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
Published: 2026-09-01
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an untrusted pointer dereference in Samsung Open Source mTower that permits pointer manipulation. If an attacker can influence the data that the software will dereference, the program may access memory that it should not, potentially corrupting memory or enabling the execution of arbitrary code. The weakness is classified as CWE-822 and could compromise confidentiality, integrity, or availability depending on the context in which mTower runs.

Affected Systems

Samsung Open Source mTower versions before commit 06994e303637512e39062f3e037c222e8448e57e are affected. The vulnerable code resides in the mTower repository and was patched in the referenced pull request.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploits are documented. Without an attack vector explicitly stated in the advisory, it is inferred that the flaw likely requires interaction with the mTower service or API, possibly exposing the risk to users who have authorized access or to processes that invoke mTower locally.

Generated by OpenCVE AI on September 1, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade mTower to commit 06994e303637512e39062f3e037c222e8448e57e or a later release that includes the patch.
  • If an upgrade is not feasible, limit access to the mTower service by restricting its network reach to trusted hosts only, thereby reducing the opportunity for exploitation.
  • Apply runtime hardening such as stack canaries and address space layout randomization to make execution of arbitrary code from a corrupted pointer more difficult.

Generated by OpenCVE AI on September 1, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption Vulnerability in Samsung Open Source mTower

Tue, 01 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-09-01T12:18:27.300Z

Reserved: 2026-08-31T11:53:17.414Z

Link: CVE-2026-82927

cve-icon Vulnrichment

Updated: 2026-09-01T12:18:19.151Z

cve-icon NVD

Status : Received

Published: 2026-09-01T11:16:45.373

Modified: 2026-09-01T13:20:04.907

Link: CVE-2026-82927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T12:30:04Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference