CVE-2026-15551: Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffer overflow when rendering a crafted Lottie animation at native canvas size
Published Jul 13, 2026
·Updated
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects .
Affected Software
1 affected component
Samsung rLottie
Event History
Jul 13, 2026
CVE Published
via MITRE·12:11 AM
Data Sourced
via MITRE·12:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15551?
The severity of CVE-2026-15551 is rated as medium at 5.5.
2
How do I fix CVE-2026-15551?
To fix CVE-2026-15551, update to the latest version of Samsung rLottie that addresses the integer overflow vulnerability.
3
What type of vulnerability is CVE-2026-15551?
CVE-2026-15551 is classified as an integer overflow vulnerability, leading to potential heap-based buffer overflow.
4
What is the impact of CVE-2026-15551?
The impact of CVE-2026-15551 includes the possibility of unauthorized access to memory, which could lead to crashes or execution of malicious code.
5
Which software is affected by CVE-2026-15551?
CVE-2026-15551 affects the Samsung Open Source rlottie library.