What is CVE-2026-21072?
An improper input validation flaw (CVE-2026-21072) in the VC1 codec within the libsavsvc.so library on Samsung Exynos processors allows local attackers to write out-of-bounds memory. This may lead to code execution depending on the architecture and version. Affected devices should be updated to SMR Aug-2026 Release 1.
Azərbaycanca: Samsung Exynos prosessorlarında istifadə olunan libsavsvc.so kitabxanasındakı VC1 kodekində daxil yoxlamanın zəifliyi (CVE-2026-21072) aşkar edilib. Bu, lokal təcavüzkarlara yaddaşda icazəsiz yazmaq imkanı verərək arxitektura və versiyadan asılı olaraq kod icrasına səbəb ola bilər. Təsirə məruz qalan qurğular üçün SMR Aug-2026 Release 1 yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ1
In which component was the CVE-2026-21072 vulnerability discovered?
This vulnerability was discovered in the VC1 codec within the libsavsvc.so library on Samsung Exynos processors.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.