{"id":"CVE-2026-47320","details":"Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads.\n\nThis issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.","modified":"2026-10-08T07:16:22.663794528Z","published":"2026-06-04T09:38:27.208Z","database_specific":{"cna_assigner":"samsung.tv_appliance","cwe_ids":["CWE-674","CWE-824"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47320.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47320.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47320"},{"type":"FIX","url":"https://github.com/Samsung/rlottie/pull/593"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samsung/rlottie","events":[{"introduced":"0"},{"fixed":"eae37633fda13ac05b25c6c95aacea4bc33c80a3"}]}],"database_specific":{"vanir_signatures_modified":"2026-10-08T07:16:22Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47320.json","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3","target":{"file":"src/lottie/lottieitem.cpp"},"deprecated":false,"digest":{"line_hashes":["213280188925596872052513713472688206278","33411903857230014257247098666930328833","63469950082630339075485683947480779172","77077896059995945326992769087433819293","132183632368912103231957727960020818576","315491606183481025321649958013006127788"],"threshold":0.9},"id":"CVE-2026-47320-152195af"},{"deprecated":false,"digest":{"line_hashes":["232405887510729199894333079770213256325","247565528567437359195070832380914296570","241216865214954983730175982005422653071","134261506741897110639672951937369211294"],"threshold":0.9},"id":"CVE-2026-47320-34a1c2d5","signature_type":"Line","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3","target":{"file":"src/lottie/lottiemodel.h"}},{"deprecated":false,"digest":{"line_hashes":["300982013454430011685817033218417586548","124154662779339202281840836375549564333","177206022484554340523065925008602851829","215476526549125499283294915656972398756"],"threshold":0.9},"id":"CVE-2026-47320-7eb7933b","signature_type":"Line","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3","target":{"file":"src/lottie/lottieitem.h"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/eae37633fda13ac05b25c6c95aacea4bc33c80a3","target":{"file":"src/lottie/lottieitem.cpp","function":"renderer::Layer::matrix"},"deprecated":false,"digest":{"function_hash":"13913743407111552725038858027819619408","length":186},"id":"CVE-2026-47320-f092e1e8"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"}]}