Impact
The LevelX NAND flash translation layer metadata parser contains an unbounded out-of-bounds heap write that overwrites a driver function pointer in the control block, allowing an attacker who can provide a crafted NAND flash image to trigger a demonstrated control-flow hijack where the RIP is set to a full 8-byte attacker-chosen value, accompanied by two out-of-bounds reads, thereby providing Remote Code Execution capability.
Affected Systems
This vulnerability affects the Eclipse Foundation's Eclipse ThreadX LevelX NAND driver; no specific release version is listed, so the issue exists in the current HEAD commit and likely persists in all recent releases. Systems that embed the LevelX driver and accept externally supplied NAND flash images are impacted.
Risk and Exploitability
The CVSS base score of 8.6 indicates a high impact risk, while the EPSS score is unavailable and the vulnerability is not listed in CISA's KEV. The attack requires the attacker to mount a custom NAND flash image, implying the need for local or physical access to the device; if such access is possible, the likelihood of exploitation is significant, warranting priority patching.
OpenCVE Enrichment