CVE-2026-6840

MEDIUM

Samsung ONE <1.30.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-129
Status published
Products (1)
Samsung Open Source/ONE 1.30.0
Published Apr 22, 2026
Tracked Since Apr 22, 2026