CVE-2026-6839

MEDIUM

Samsung Open Source One < 1.30.0 - Out-of-Bounds Access

Title source: rule
STIX 2.1

Description

Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0.

Scores

CVSS v3 6.6
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (2)
samsung/one < 1.30.0
Samsung Open Source/ONE 1.30.0
Published Apr 22, 2026
Tracked Since Apr 22, 2026