In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module memory region.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 07:30:00 +0000

Type Values Removed Values Added
Description In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module memory region.
Title Incomplete validation of kernel object pointers in system calls
Weaknesses CWE-233
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2025-10-14T15:29:21.710Z

Reserved: 2025-08-06T18:32:14.665Z

Link: CVE-2025-55078

cve-icon Vulnrichment

Updated: 2025-10-14T15:29:17.344Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-14T08:15:36.173

Modified: 2025-10-14T19:36:29.240

Link: CVE-2025-55078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.