CVE-2026-40448

MEDIUM

Samsung ONE <1.30.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit  1.30.0.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (3)
samsung/one < 1.30.0
Samsung Open Source/ONE 1.30.0
Samsung Open Source/ONE 95fba2da1880ab3eabc719520e8591c33b65b272
Published Apr 22, 2026
Tracked Since Apr 22, 2026