Double free in Samsung products - CVE-2026-23790
Published: June 1, 2026
Exynos 1280
Exynos 2200
Exynos 1380
Exynos 1480
Exynos 2400
Exynos 1580
Exynos 2500
Exynos 1680
Exynos 2600
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack. .
The vulnerability exists due to improper pointer management during DMA buffer reallocation in the Samsung Exynos DPU driver. A remote attacker can pass specially crafted data to the application, trigger double free error and cause a denial of service condition on the target system.