CVE-2026-23791: Samsung Exynos 1280 Firmware

Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.

Affected products

  • Samsung Exynos 1280 Firmware: up to and including 2025-12-29

Published 2026-09-14. Last modified 2026-09-22.