VYPR
Unrated severityNVD Advisory· Published Apr 11, 2022· Updated Aug 3, 2024

CVE-2022-26095

CVE-2022-26095

Description

Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A null pointer dereference in the libsimba library's parser_colr function allows an unauthenticated remote attacker to cause an out-of-bounds write on Samsung mobile devices with Android prior to the SMR Apr-2022 Release 1.

Vulnerability

The vulnerability resides in the parser_colr function of the libsimba library, which is used on Samsung mobile devices. A null pointer dereference occurs when processing specially crafted data, enabling an out-of-bounds write. Affected versions are those using libsimba prior to the Samsung Mobile Security (SMR) Apr-2022 Release 1 [1].

Exploitation

An attacker can exploit this vulnerability remotely without authentication. By delivering a maliciously crafted input to the parser_colr function, the null pointer dereference is triggered, leading to a write operation outside the intended memory bounds [1]. No user interaction is required if the attack vector is network-based.

Impact

Successful exploitation results in an out-of-bounds write, which can lead to memory corruption. The attacker may achieve arbitrary code execution or cause a denial of service. The impact is critical as it enables remote compromise of the device without privileges [1].

Mitigation

Samsung released the fix as part of the SMR Apr-2022 Release 1 security update for Android. Users should apply the update promptly via the device's software update mechanism [1]. No workarounds are described; updating is the only mitigation.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.