Junglewise Threat Intelligence

CVE-2026-23790: Samsung Exynos DPU double-free vulnerability

CVE-2026-23790 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 2200, Samsung Exynos 1380, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 2500, Samsung Exynos 2600, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors contain a critical flaw in the Display Processing Unit (DPU) driver that can lead to kernel-level memory corruption. A malicious actor with access to DMA buffer operations could exploit improper pointer management to trigger a double-free condition, potentially crashing the device or executing arbitrary code with kernel privileges.

Technical details

A double-free vulnerability exists in the Samsung Exynos DPU driver due to improper pointer management during DMA buffer reallocation. The vulnerability allows an attacker to free the same memory location twice, leading to kernel heap corruption and potential use-after-free conditions. Attack preconditions and vector details are not fully specified in available documentation, but exploitation could result in denial of service or privilege escalation depending on memory layout and kernel protections. Affected Exynos processors include models 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. Patch status and mitigation availability require verification with Samsung security updates.

Affected products

  • Samsung Exynos 1280
  • Samsung Exynos 2200
  • Samsung Exynos 1380
  • Samsung Exynos 1480
  • Samsung Exynos 2400
  • Samsung Exynos 1580
  • Samsung Exynos 2500
  • Samsung Exynos 1680
  • Samsung Exynos 2600

Timeline

  • 2026-09-14: disclosed

References

Related threats