๐Ÿ” CVE Alert

CVE-2026-86314

MEDIUM 6.2
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.

CWE CWE-190
Vendor samsung opensource
Product walrus
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for samsung opensource walrus

Be the first to know when new medium vulnerabilities affecting samsung opensource walrus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Samsung Opensource / Walrus
ff3bf5ff5c4878f8e5572c9593d303f6bc997443

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Samsung/walrus/pull/482

Credits

Ezinne Kalu