Home

Description

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

PUBLISHED Reserved 2026-05-19 | Published 2026-06-04 | Updated 2026-06-07 | Assigner samsung.tv_appliance




MEDIUM: 6.1CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Problem types

CWE-824 Access of uninitialized pointer

CWE-674 Uncontrolled Recursion

Product status

Default status
affected

eae37633fda13ac05b25c6c95aacea4bc33c80a3
unaffected

References

github.com/Samsung/rlottie/pull/593

cve.org (CVE-2026-47320)

nvd.nist.gov (CVE-2026-47320)

Download JSON