ZeroHour

CVE-2026-86313

niche

Out-of-Bounds Write in Samsung Opensource Walrus

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

Samsung's open-source Walrus library contains an out-of-bounds write (CWE-787) involving overflow buffers, tracked as CVE-2026-86313 and rated 7.8 (High) with a local attack vector (AV:L) that requires user interaction (UI:R). The flaw is tied to the code at commit af80e665ea49d9003695a66502f841ed1d8397e7; exploitation would require a local attacker to get a user to run a process or feed data through the vulnerable Walrus code path, after which the memory corruption can deliver high-impact confidentiality, integrity, and availability consequences (i.e., potential code execution with the privileges of the affected process). Only projects and builds that incorporate Walrus at this specific commit are affected, since the advisory identifies the flaw by commit hash rather than by a released version. There is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.1% chance of exploitation within 30 days (2nd percentile), so no in-the-wild exploitation is currently known.

What to do: Check whether your builds pin or embed Walrus at commit af80e665ea49d9003695a66502f841ed1d8397e7 and update to the patched revision published in Samsung's Walrus repository once a fix is released (no fixed version is specified in the advisory). Given the local, user-interaction-gated attack vector and the very low EPSS score, treat this as low urgency, prioritizing remediation only where the library processes untrusted local input.

Affected
Samsung Opensource Walruscommit af80e665ea49d9003695a66502f841ed1d8397e7 (only version identifier provided in the advisory; no released version numbers specified)
Estimated exposure
nicheunknown; likely small - a niche open-source project consumed directly from source at a specific commit — Walrus is identified by a source commit hash with no published install counts, distribution or product shipping data, or internet-exposed footprint, and the local attack vector limits blast radius to downstream builds integrating that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.