CVE-2026-40450
בינונית 6.6
תיאור (מקור, אנגלית)
Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected version is prior to commit 1.30.0.
מדדים
- CVSS 3.1
-
6.6 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-25/9/2026
- CWE
- CWE-190
מוצרים מושפעים
samsung: one
קישורים
- https://github.com/Samsung/ONE/pull/16481 Issue TrackingPatch