Impact
An out‑of‑bounds write in Samsung Opensource Walrus introduces a buffer overflow that could allow an attacker to corrupt memory and potentially execute arbitrary code. The vulnerability permits writing beyond the intended buffer boundaries, which can lead to unpredictable behaviour, loss of confidentiality, integrity, or availability of the affected system.
Affected Systems
The issue affects the Walrus project maintained by Samsung Opensource. Affected code is identified by the commit hash af80e665ea49d9003695a66502f841ed1d8397e7. Any deployment of Walrus that includes this commit is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks the flaw as high severity. No EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. Attack exploitation would likely require access to the application environment, suggesting a local or privileged user could trigger the overflow by feeding crafted input to Walrus. Because the CVSS base score reflects High impact, organizations should treat this as a significant risk pending a fix.
OpenCVE Enrichment