CVE-2026-40450 is an integer overflow vulnerability in Samsung Open Source ONE that affects tensor processing operations prior to version 1.30.0. The flaw occurs in the output tensor copy size calculation, potentially causing incorrect copy lengths and memory corruption when handling oversized tensors. The vulnerability has a CVSS score of 6.6 (Medium severity) with a local attack vector requiring no privileges but user interaction. While the complexity is low, the potential impact includes confidentiality loss, integrity compromise, and high availability impact through memory corruption. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, remains inactive on security hot lists, and has minimal community attention based on its low EPSS score of 0.00015. Organizations should prioritize patching to version 1.30.0 or later, particularly systems using Samsung Open Source ONE with untrusted input sources.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.