Impact
The gx_binres_theme_load function in Eclipse Foundation GUIX allocates a zero‑byte buffer when a requested theme ID is beyond the declared theme count. The subsequent loading routine then treats arbitrary data that follows the table as a theme header and writes a GX_THEME structure into that zero‑byte buffer. This out‑of‑bounds write leads to a heap‑based buffer overflow, compromising memory integrity and potentially allowing an attacker to execute arbitrary code or disrupt service. The weakness is reflected in CWE‑131 for incorrect size calculation and CWE‑787 for buffer overflow.
Affected Systems
This vulnerability affects the GUIX component provided by the Eclipse Foundation. No specific version information is available in the advisory; users should verify the version of GUIX installed in their environments and compare it against any vendor‑issued updates that address this issue.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, but the lack of an EPSS score and absence from the CISA KEV catalog imply limited current exploitation data. Nevertheless, the flaw allows uncontrolled writes to memory; if an attacker can provide a malicious theme ID or suppress the theme count check, they could potentially crash the application or gain code execution. The likely attack vector involves supplying a manipulated theme resource file or altering theme configuration data; further exploitation would require that the affected GUIX instance processes such a resource.
OpenCVE Enrichment