CVE-2026-86314
Dashboard / Vulnerabilities / CVE-2026-86314
CVE-2026-86314
Published: 7 Sept 2026Last Modified: 8 Oct 2026
Summary:
Details: Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86314.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86314, https://github.com/Samsung/walrus/pull/482
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- ff3bf5ff5c4878f8e5572c9593d303f6bc997443
Fixed -None
Affected versions
ff3bf5ff5c4878f8e5572c9593d303f6bc997443
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
