Description
`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.
Published: 2026-09-29
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Memory Corruption
Action: Apply Patch
AI Analysis

Impact

The gx_binres_theme_load function in Eclipse Foundation GUIX allocates a zero‑byte buffer when a requested theme ID is beyond the declared theme count. The subsequent loading routine then treats arbitrary data that follows the table as a theme header and writes a GX_THEME structure into that zero‑byte buffer. This out‑of‑bounds write leads to a heap‑based buffer overflow, compromising memory integrity and potentially allowing an attacker to execute arbitrary code or disrupt service. The weakness is reflected in CWE‑131 for incorrect size calculation and CWE‑787 for buffer overflow.

Affected Systems

This vulnerability affects the GUIX component provided by the Eclipse Foundation. No specific version information is available in the advisory; users should verify the version of GUIX installed in their environments and compare it against any vendor‑issued updates that address this issue.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity, but the lack of an EPSS score and absence from the CISA KEV catalog imply limited current exploitation data. Nevertheless, the flaw allows uncontrolled writes to memory; if an attacker can provide a malicious theme ID or suppress the theme count check, they could potentially crash the application or gain code execution. The likely attack vector involves supplying a manipulated theme resource file or altering theme configuration data; further exploitation would require that the affected GUIX instance processes such a resource.

Generated by OpenCVE AI on September 29, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest GUIX release that includes a bounds check for theme IDs before allocating buffers.
  • If an updated release is not yet available, restrict the ability to load themes to trusted users or processes and disable loading of external theme resources.
  • Add defensive checks in any custom theme loader integration to verify that the requested theme ID is within the declared theme count before allocating memory.

Generated by OpenCVE AI on September 29, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GUIX Theme Loader

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.
Weaknesses CWE-131
CWE-787
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:26:36.721Z

Reserved: 2026-09-29T16:15:23.083Z

Link: CVE-2026-102729

cve-icon Vulnrichment

Updated: 2026-09-29T18:26:31.353Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:12.620

Modified: 2026-09-29T19:17:23.390

Link: CVE-2026-102729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-787

    Out-of-bounds Write