Junglewise Threat Intelligence

CVE-2026-23786: Samsung Exynos DRM HDR Driver race condition in DPU

CVE-2026-23786 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 2200, Samsung Exynos 1380, Samsung Exynos 2600, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors include a display processing unit (DPU) with a DRM HDR driver that is vulnerable to a race condition. An attacker can exploit this timing vulnerability to cause memory access errors, potentially crashing the system or causing unpredictable behavior that affects device stability and user experience.

Technical details

A time-of-check-time-of-use (TOCTOU) race condition exists in the Exynos DRM HDR Driver component of the DPU (Display Processing Unit). The vulnerability allows an attacker to trigger a heap overflow through careful timing manipulation between validation and use of memory addresses. The attack likely requires local access to trigger driver operations. Exploitation results in memory access errors that can cause kernel crashes or system instability. Samsung has acknowledged the issue and patches are expected to be available through security updates.

Affected products

  • Samsung Exynos 1280 all versions
  • Samsung Exynos 2200 all versions
  • Samsung Exynos 1380 all versions
  • Samsung Exynos 1480 all versions
  • Samsung Exynos 2400 all versions
  • Samsung Exynos 1580 all versions
  • Samsung Exynos 2500 all versions
  • Samsung Exynos 1680 all versions
  • Samsung Exynos 2600 all versions

Timeline

  • 2026-09-14: disclosed
  • 2025-12-24: other: Reported date

References

Related threats