# CVE-2026-86314

## Summary

- **CVE ID:** CVE-2026-86314
- **Severity:** MEDIUM
- **CVSS Score:** 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-190
- **Published:** Sep 7, 2026
- **Last Modified:** Sep 8, 2026

## Description

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.



This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.

## Affected Products

- Samsung Opensource — Walrus (ff3bf5ff5c4878f8e5572c9593d303f6bc997443)

## References

- [CNA](https://github.com/Samsung/walrus/pull/482)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._