BRIEFING NOTE ON CVE-2026-41666 An integer overflow vulnerability exists in Samsung Open Source ONE's tensor copy size calculation that could allow out-of-bounds memory access during loop state propagation. The vulnerability affects all versions prior to commit 1.30.0 and stems from improper handling of numerical calculations that determine memory allocation boundaries. The vulnerability carries a CVSS score of 6.6 (Medium severity) with a local attack vector requiring user interaction. Attack complexity is low, and while confidentiality and integrity impacts are limited, the availability impact is rated as high, indicating potential for denial of service or system crashes. The vulnerability requires local access and user action to exploit. No active exploitation or proof-of-concept code is currently documented in known exploit databases. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score indicating very low probability of exploitation in the wild. Organizations should prioritize patching based on their use of Samsung Open Source ONE rather than immediate threat indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.