๐Ÿ” CVE Alert

CVE-2026-102709

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.

CWE CWE-200 CWE-501 CWE-822
Vendor eclipse foundation
Product threadx
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation threadx

Be the first to know when new unknown vulnerabilities affecting eclipse foundation threadx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / ThreadX
0 โ‰ค 6.5.1.202602

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-ffg5-m7vh-vwrp

Credits

๐Ÿ” jovanbulck ๐Ÿ” btijs ๐Ÿ” martonbognar ๐Ÿ” antonislouca