Description
Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.

This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
Published: 2026-09-07
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential arbitrary code execution
Action: Apply patch
AI Analysis

Impact

An out‑of‑bounds write in Samsung Opensource Walrus introduces a buffer overflow that could allow an attacker to corrupt memory and potentially execute arbitrary code. The vulnerability permits writing beyond the intended buffer boundaries, which can lead to unpredictable behaviour, loss of confidentiality, integrity, or availability of the affected system.

Affected Systems

The issue affects the Walrus project maintained by Samsung Opensource. Affected code is identified by the commit hash af80e665ea49d9003695a66502f841ed1d8397e7. Any deployment of Walrus that includes this commit is vulnerable.

Risk and Exploitability

The CVSS score of 7.8 marks the flaw as high severity. No EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. Attack exploitation would likely require access to the application environment, suggesting a local or privileged user could trigger the overflow by feeding crafted input to Walrus. Because the CVSS base score reflects High impact, organizations should treat this as a significant risk pending a fix.

Generated by OpenCVE AI on September 7, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Walrus to a release that excludes commit af80e665ea49d9003695a66502f841ed1d8397e7.
  • If upgrading is not yet possible, isolate Walrus in a restricted environment and limit untrusted input to reduce the risk of triggering the overflow.
  • Review and enforce proper input validation and buffer size checks in any custom code that extends Walrus to ensure no out‑of‑bounds writes can occur.

Generated by OpenCVE AI on September 7, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Open Source
Samsung Open Source walrus
Vendors & Products Samsung Open Source
Samsung Open Source walrus

Mon, 07 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Samsung Open Source Walrus
cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-09-08T15:27:26.892Z

Reserved: 2026-09-07T02:00:03.744Z

Link: CVE-2026-86313

cve-icon Vulnrichment

Updated: 2026-09-08T15:27:15.385Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T03:17:19.407

Modified: 2026-09-08T19:09:50.263

Link: CVE-2026-86313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T04:30:16Z

Weaknesses