Junglewise Threat Intelligence

CVE-2026-23791: Samsung Exynos DPU out-of-bounds write in color mode LUT parsing

CVE-2026-23791 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 2200, Samsung Exynos 1380, Samsung Exynos 2600, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors contain a vulnerability in the Display Processing Unit (DPU) driver that can corrupt kernel memory due to insufficient input validation. An attacker could exploit this flaw to potentially escalate privileges and take unauthorized control of the device or access sensitive data.

Technical details

The vulnerability is an out-of-bounds write in the Exynos DPU driver caused by missing input length validation during color mode Look-Up Table (LUT) parsing. The flaw allows an attacker to write beyond allocated buffer boundaries, corrupting kernel memory structures. Exploitation requires local access to invoke the vulnerable driver code path, but successful exploitation can lead to kernel memory corruption and potential privilege escalation. The issue affects multiple Exynos processor variants (1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, 2600). Patches from Samsung are expected to address this input validation gap.

Affected products

  • Samsung Exynos 1280 all
  • Samsung Exynos 2200 all
  • Samsung Exynos 1380 all
  • Samsung Exynos 1480 all
  • Samsung Exynos 2400 all
  • Samsung Exynos 1580 all
  • Samsung Exynos 2500 all
  • Samsung Exynos 1680 all
  • Samsung Exynos 2600 all

Timeline

  • 2026-09-14: disclosed
  • 2025-12-29: advisory: Reported date per Samsung advisory

References

Related threats