๐Ÿ” CVE Alert

CVE-2026-102730

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack โ€” RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" โ€” an AI-generated parser with an unchecked on-flash count.)

CWE CWE-787 CWE-1284
Vendor eclipse foundation
Product eclipse-threadx/levelx(nand driver)
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse-threadx/levelx(nand driver)

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse-threadx/levelx(nand driver) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / eclipse-threadx/levelx(NAND driver)
HEAD `9f1cfdc` and prior; Finding 1 introduced by commit `47b2a17d`; Finding 2 is the un-patched half of the Nov-2025 fix `0f7dd521`.

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g

Credits

๐Ÿ” adawn0106