CVE-2026-6839Disclosure(samsung / one)

LOWCVSS 6.6 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • one

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
one

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-23: 2Technical Details · 2026-04-23: 204-23
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6839 Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source… https://www.cve.org/CVERecord?id=CVE-2026-6839 ----- Traducción: CVE-2026-6839 Val… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-6839, noting an out‑of‑bounds memory issue in Samsung Open Source due to improper validation of STRING tensor offsets, but provides no PoC, exploit, or patch details.

    0000035
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6839 Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source… https://www.cve.org/CVERecord?id=CVE-2026-6839

    Post summary

    The text provides a brief disclosure of CVE-2026-6839, describing an improper validation issue that can lead to out-of-bounds access in Samsung Open Source.

    00000150
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungone---

Explore more