← All Advisories

CVE-2026-23789

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-23789

Key Details

CVECVE-2026-23789
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSamsung Exynos 850 firmware
Classified asCWE-415 (Double Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SamsungExynos 850 firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution. (NVD)

What to Do

Monitor Samsung's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-23789
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-23789