Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86314

Quick assessment

Affected
Samsung Opensource Walrus
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述信息的中文翻译: 漏洞描述翻译: 在 Samsung 的 Walrus 运行时(所有平台)中, 函数(位于 )中的源边界检查存在整数溢出漏洞。远程攻击者可以通过构造一个特定的 WebAssembly 模块来触发该漏洞:其中 32 位无符号加法发生回绕(wrap-around),从而绕过边界检查,导致堆越界读取(out-of-bounds heap read),最终造成拒绝服务(DoS)。 该问题影响版本:Walrus 提交 。 --- 关键术语说明(供参考): Integer overflow(整

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86314

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Samsung Opensource Walrus ff3bf5ff5c4878f8e5572c9593d303f6bc997443 -

II. Public POCs for CVE-2026-86314

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86314

登录查看更多情报信息。

Patches & Fixes for CVE-2026-86314 (1)

Same Patch Batch · Samsung Opensource · 2026-09-07 · 3 CVEs total

CVE-2026-86313 7.8 HIGH 三星Walrus缓冲区溢出漏洞
CVE-2026-86315 6.2 MEDIUM Escargot x86-64 整数截断导致越界写

IV. Related Vulnerabilities

V. Comments for CVE-2026-86314

No comments yet


Leave a comment