CVE-2026-47320

Source
https://cve.org/CVERecord?id=CVE-2026-47320
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47320.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47320
Downstream
Published
2026-06-04T09:38:27Z
Modified
2026-10-08T07:16:22Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads.

This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Database specific
{
    "cna_assigner": "samsung.tv_appliance",
    "cwe_ids": [
        "CWE-674",
        "CWE-824"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47320.json"
}
References

Affected packages

Git / github.com/samsung/rlottie

Affected ranges

Type
GIT
Repo
https://github.com/samsung/rlottie
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47320.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "213280188925596872052513713472688206278",
                "33411903857230014257247098666930328833",
                "63469950082630339075485683947480779172",
                "77077896059995945326992769087433819293",
                "132183632368912103231957727960020818576",
                "315491606183481025321649958013006127788"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-47320-152195af",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3",
        "target": {
            "file": "src/lottie/lottieitem.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "232405887510729199894333079770213256325",
                "247565528567437359195070832380914296570",
                "241216865214954983730175982005422653071",
                "134261506741897110639672951937369211294"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-47320-34a1c2d5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3",
        "target": {
            "file": "src/lottie/lottiemodel.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "300982013454430011685817033218417586548",
                "124154662779339202281840836375549564333",
                "177206022484554340523065925008602851829",
                "215476526549125499283294915656972398756"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-47320-7eb7933b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3",
        "target": {
            "file": "src/lottie/lottieitem.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "13913743407111552725038858027819619408",
            "length": 186
        },
        "id": "CVE-2026-47320-f092e1e8",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3",
        "target": {
            "file": "src/lottie/lottieitem.cpp",
            "function": "renderer::Layer::matrix"
        }
    }
]
vanir_signatures_modified
"2026-10-08T07:16:22Z"