CVE-2026-20973Out-of-bounds Read in Samsung Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
9.1CRITICALNVD
CNA5.3
EPSS
0.0%
top 94.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 9

Description

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

NVDsamsung/android4 versions+3

🔴Vulnerability Details

2
CVEList
CVE-2026-20973: Out-of-bounds read in libimagecodec2026-01-09
GHSA
GHSA-f5wv-cvx7-7x88: Out-of-bounds read in libimagecodec2026-01-09

🕵️Threat Intelligence

1
Wiz
CVE-2026-20973 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-20973 — Out-of-bounds Read in Samsung Android | cvebase