CRITICAL 9.2 NVD

CVE-2026-21095

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Affected Products

References

Published: 2026-09-09 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-09 via NVD. Affected: samsung/android.

Risk Timeline

CVE Disclosed2026-09-09 · 1 day ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-21102Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privilegeCRITICAL9.3
CVE-2026-21096Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMCRITICAL9.2
CVE-2026-21092Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attacHIGH8.8
CVE-2026-21087Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local HIGH8.6
CVE-2026-21085Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allowsHIGH8.4
CVE-2026-21101Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 alloHIGH8.4
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.