Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41665

22
FAUCET Score

CVE-2026-41665 is an integer overflow vulnerability in Samsung Open Source ONE's scratch buffer initialization that results in incorrect memory allocation for large intermediate tensors. The flaw affects all versions prior to commit 1.30.0. This memory initialization error could allow local attackers with user-level privileges to cause system instability or data corruption through the tensor processing functionality. The vulnerability carries a CVSS severity score of 6.1 (Medium) with a local attack vector requiring no special privileges and user interaction. While the attack complexity is low, the impact is primarily focused on availability and integrity, with no confidentiality exposure. The EPSS score of 0.00013 indicates minimal statistical likelihood of exploitation compared to other disclosed vulnerabilities. There is currently no evidence of active exploitation or public exploit code availability. The vulnerability has not been designated as a Known Exploited Vulnerability (KEV) by CISA, and community attention remains inactive. Organizations using Samsung Open Source ONE should prioritize updating to version 1.30.0 or later as part of routine patch management, though immediate emergency response is not required.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.30.0CPE matchmatch criteria
cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 4th percentile among its peer group of 5,758 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / Samsung/ONE/pull/16481
Issue TrackingPatch