Junglewise Threat Intelligence

CVE-2026-23787: Samsung Exynos DRM HDR use-after-free in DPU

CVE-2026-23787 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 2200, Samsung Exynos 1380, Samsung Exynos 2600, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors contain a use-after-free vulnerability in the Display Processing Unit (DPU) driver that can be triggered by improper cleanup when memory mapping operations fail. An attacker with local access to kernel interfaces could trigger a kernel crash, disrupting device operation and potentially enabling further system compromise.

Technical details

A use-after-free vulnerability exists in the Exynos DRM HDR driver (DPU component) across multiple processor generations. The root cause is improper cleanup and error handling when vmap (kernel virtual memory mapping) operations fail, leaving freed memory references accessible. The vulnerability is triggered through local attack vectors; remote exploitation is unlikely unless combined with other privilege escalation techniques. Successful exploitation results in a kernel crash (denial of service), and may permit reading or writing kernel memory depending on heap state and attacker capabilities. Samsung has acknowledged the issue with a reported date of 2025-12-24.

Affected products

  • Samsung Exynos 1280 <UNKNOWN>
  • Samsung Exynos 2200 <UNKNOWN>
  • Samsung Exynos 1380 <UNKNOWN>
  • Samsung Exynos 1480 <UNKNOWN>
  • Samsung Exynos 2400 <UNKNOWN>
  • Samsung Exynos 1580 <UNKNOWN>
  • Samsung Exynos 2500 <UNKNOWN>
  • Samsung Exynos 1680 <UNKNOWN>
  • Samsung Exynos 2600 <UNKNOWN>

Timeline

  • 2026-09-14: disclosed
  • 2025-12-24: other: Reported date per Samsung

References

Related threats