CVE-2026-23790

Summary

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.

Affected Software

VendorProductVersion RangeStatus
SamsungExynos 1280 firmware0 <= 2025-12-29affected

Weaknesses

  • CWE-415: CWE-415 Double Free

References