PatchSiren cyber security CVE debrief
CVE-2026-47307 Samsung Open Source CVE debrief
A NULL pointer dereference vulnerability exists in Samsung Open Source Walrus, a WebAssembly runtime. The flaw can be triggered by a crafted WebAssembly module containing deeply nested instructions, resulting in denial of service. The vulnerability affects Walrus commit f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9. A fix has been proposed via pull request.
- Vendor
- Samsung Open Source
- Product
- Walrus
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
Organizations operating WebAssembly execution services using Samsung Walrus, developers building applications with Walrus runtime, security teams monitoring WebAssembly supply chain risks, and infrastructure providers accepting untrusted WebAssembly modules from external sources.
Technical summary
The vulnerability stems from improper handling of deeply nested instructions in WebAssembly modules within the Walrus runtime. When processing a maliciously crafted module with excessive nesting depth, the runtime dereferences a NULL pointer, causing a crash and denial of service. The attack requires local access and user interaction to trigger, limiting its severity. The issue is specific to commit f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9 of the Samsung Walrus project. A remediation pull request has been submitted to address the underlying NULL pointer dereference condition.
Defensive priority
medium
Recommended defensive actions
- Review and apply the fix from Samsung Walrus pull request 409 when available
- Validate WebAssembly module nesting depth before processing untrusted inputs
- Monitor Samsung Walrus repository for official security advisory and patched release
- Implement input validation and sandboxing for WebAssembly execution environments
- Assess exposure of Walrus-based services to untrusted WebAssembly module ingestion
Evidence notes
The CVE description identifies the affected component as Samsung Open Source Walrus, a WebAssembly runtime engine. The vulnerability is classified as CWE-476 (NULL Pointer Dereference). The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates a local attack vector requiring user interaction, with high availability impact. A pull request addressing this issue has been submitted to the Samsung Walrus repository.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47307 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47307
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47307 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47307
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Samsung/walrus/pull/409
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.