Junglewise Threat Intelligence

CVE-2026-21068: Samsung libril_sem stack-based buffer overflow

CVE-2026-21068 · Severity: high · CVSS 7.8 · Published 2026-08-10

Technologies: Samsung Mobile Firmware. Vendors: Samsung.

Executive brief

libril_sem.so is a critical telephony component in Samsung mobile devices that handles radio interface communication. A stack-based buffer overflow vulnerability allows privileged local attackers to execute arbitrary code with elevated privileges, potentially compromising the entire device and all data stored on it.

Technical details

A stack-based buffer overflow exists in libril_sem.so prior to the August 2026 SMR Release 1. The vulnerability is triggered by local attack vectors and requires privilege escalation or an already-privileged execution context. An attacker with local access and sufficient privileges can overflow the stack to overwrite return addresses or other control flow data, achieving arbitrary code execution. The vulnerability affects Samsung mobile firmware versions before the August 2026 security patch; patches are available in SMR Aug-2026 Release 1 and later.

Affected products

  • Samsung Mobile Firmware before August 2026 SMR Release 1

Timeline

  • 2026-08-10: disclosed
  • 2026-08: patched: SMR Aug-2026 Release 1

References

Related threats