CVE-2026-41667 is an integer overflow vulnerability in Samsung Open Source ONE prior to version 1.30.0 that affects the constant tensor data size calculation, potentially resulting in incorrect buffer sizing for large constant nodes. The flaw could lead to memory corruption issues during processing of maliciously crafted neural network models. The vulnerability carries a CVSS 3.1 score of 6.6 (Medium) with a local attack vector requiring no privileges but user interaction, affecting confidentiality, integrity, and availability of the target system. The FAUCET Risk Score of 45.0/100 indicates moderate organizational risk, though the extremely low EPSS score of 0.000120000 suggests minimal real-world exploitation probability. There is no evidence of active exploitation, no public exploit code availability, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal, with the vulnerability classified as inactive on threat tracking lists, indicating this remains a lower-priority remediation concern despite its technical severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.