CVE-2026-86314
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.
This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Samsung Opensource | Walrus | ff3bf5ff5c4878f8e5572c9593d303f6bc997443 | affected |
Weaknesses
- CWE-190: CWE-190 Integer overflow or wraparound
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.