CVE-2026-41665 is an integer overflow vulnerability in Samsung Open Source ONE's scratch buffer initialization that results in incorrect memory allocation for large intermediate tensors. The flaw affects all versions prior to commit 1.30.0. This memory initialization error could allow local attackers with user-level privileges to cause system instability or data corruption through the tensor processing functionality. The vulnerability carries a CVSS severity score of 6.1 (Medium) with a local attack vector requiring no special privileges and user interaction. While the attack complexity is low, the impact is primarily focused on availability and integrity, with no confidentiality exposure. The EPSS score of 0.00013 indicates minimal statistical likelihood of exploitation compared to other disclosed vulnerabilities. There is currently no evidence of active exploitation or public exploit code availability. The vulnerability has not been designated as a Known Exploited Vulnerability (KEV) by CISA, and community attention remains inactive. Organizations using Samsung Open Source ONE should prioritize updating to version 1.30.0 or later as part of routine patch management, though immediate emergency response is not required.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.