CVE-2026-23791EPSS p0.5%

CVE-2026-23791CVE-2026-23791

Description

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.

Scoring

CVSS 4.2 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
EPSS0.09% probability of exploitation · percentile 0.5% · 2026-10-06T12:00:23Z
Last modified2026-09-22
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.