CVE-2026-41664 is an integer overflow vulnerability in Samsung Open Source ONE that affects versions prior to 1.30.0, potentially allowing invalid memory operations when processing large tensor shapes during memory copy operations. The vulnerability stems from improper size calculation in memory copy functions, which could be exploited to trigger memory corruption or other unintended behavior. The vulnerability carries a CVSS score of 6.6 (Medium severity) and requires local access with user interaction to exploit, though it can result in information disclosure, integrity compromise, and availability impact. Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed on the KEV catalog, and community attention remains minimal with a FAUCET risk score of 45.0. Organizations running Samsung Open Source ONE should prioritize upgrading to version 1.30.0 or later to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.