CVE-2026-23790: Double Free
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
Affected Software
Event History
Frequently Asked Questions
Which hardware should be included in impact scoping?
Systems using Samsung Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, or 2600 processors are identified as affected.
What level of attacker access is required?
Exploitation requires local access and low privileges. It does not require user interaction, but the attack complexity is rated high.
What is the expected security impact if exploitation succeeds?
The supplied vector indicates low integrity and availability impact, no confidentiality impact, and a changed scope. The issue can cause kernel memory corruption and a potential use-after-free.