Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.
This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/Samsung/walrus/pull/482 |
|
History
Mon, 07 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samsung Open Source
Samsung Open Source walrus |
|
| Vendors & Products |
Samsung Open Source
Samsung Open Source walrus |
Mon, 07 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443. | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: samsung.tv_appliance
Published:
Updated: 2026-09-07T02:22:42.210Z
Reserved: 2026-09-07T02:12:49.429Z
Link: CVE-2026-86314
No data.
Status : Received
Published: 2026-09-07T03:17:19.530
Modified: 2026-09-07T03:17:19.530
Link: CVE-2026-86314
No data.
OpenCVE Enrichment
Updated: 2026-09-07T03:30:16Z
Weaknesses