CVE-2026-86313
nicheOut-of-Bounds Write in Samsung Opensource Walrus
Samsung's open-source Walrus library contains an out-of-bounds write (CWE-787) involving overflow buffers, tracked as CVE-2026-86313 and rated 7.8 (High) with a local attack vector (AV:L) that requires user interaction (UI:R). The flaw is tied to the code at commit af80e665ea49d9003695a66502f841ed1d8397e7; exploitation would require a local attacker to get a user to run a process or feed data through the vulnerable Walrus code path, after which the memory corruption can deliver high-impact confidentiality, integrity, and availability consequences (i.e., potential code execution with the privileges of the affected process). Only projects and builds that incorporate Walrus at this specific commit are affected, since the advisory identifies the flaw by commit hash rather than by a released version. There is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.1% chance of exploitation within 30 days (2nd percentile), so no in-the-wild exploitation is currently known.
What to do: Check whether your builds pin or embed Walrus at commit af80e665ea49d9003695a66502f841ed1d8397e7 and update to the patched revision published in Samsung's Walrus repository once a fix is released (no fixed version is specified in the advisory). Given the local, user-interaction-gated attack vector and the very low EPSS score, treat this as low urgency, prioritizing remediation only where the library processes untrusted local input.
| Samsung Opensource Walrus | commit af80e665ea49d9003695a66502f841ed1d8397e7 (only version identifier provided in the advisory; no released version numbers specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.