CVE-2026-40449
בינונית 6.6
תיאור (מקור, אנגלית)
Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0.
מדדים
- CVSS 3.1
-
6.6 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-25/9/2026
- CWE
- CWE-190
מוצרים מושפעים
samsung: one
קישורים
- https://github.com/Samsung/ONE/pull/16481 Issue TrackingPatch