Junglewise Threat Intelligence

CVE-2026-21072: Samsung libsavsvc VC1 codec out-of-bounds write

CVE-2026-21072 · Severity: high · CVSS 7.8 · Published 2026-08-10

Vendors: Samsung.

Executive brief

A video codec library used in Samsung devices contains improper input validation that allows local attackers to write data beyond allocated memory boundaries. This memory corruption vulnerability could be leveraged to crash the device, corrupt data, or potentially execute arbitrary code with elevated privileges.

Technical details

The vulnerability exists in libsavsvc.so, a system library handling VC1 video codec operations, due to improper input validation when processing VC1 encoded video frames. The flaw allows a local attacker with user-level access to craft malicious VC1 video input that triggers an out-of-bounds write operation in the codec's memory buffer. This memory corruption could lead to denial of service, data integrity violation, or privilege escalation depending on the memory layout and exploitation technique. The patch was included in Samsung's August 2026 Security Maintenance Release (SMR) 1.

Affected products

  • Samsung Galaxy Mobile Devices (affected firmware) prior to SMR Aug-2026 Release 1

Timeline

  • 2026-08-10: disclosed
  • 2026-08: patched: Included in SMR Aug-2026 Release 1

References