Description
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)
Published: 2026-09-29
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The LevelX NAND flash translation layer metadata parser contains an unbounded out-of-bounds heap write that overwrites a driver function pointer in the control block, allowing an attacker who can provide a crafted NAND flash image to trigger a demonstrated control-flow hijack where the RIP is set to a full 8-byte attacker-chosen value, accompanied by two out-of-bounds reads, thereby providing Remote Code Execution capability.

Affected Systems

This vulnerability affects the Eclipse Foundation's Eclipse ThreadX LevelX NAND driver; no specific release version is listed, so the issue exists in the current HEAD commit and likely persists in all recent releases. Systems that embed the LevelX driver and accept externally supplied NAND flash images are impacted.

Risk and Exploitability

The CVSS base score of 8.6 indicates a high impact risk, while the EPSS score is unavailable and the vulnerability is not listed in CISA's KEV. The attack requires the attacker to mount a custom NAND flash image, implying the need for local or physical access to the device; if such access is possible, the likelihood of exploitation is significant, warranting priority patching.

Generated by OpenCVE AI on September 29, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch for the LevelX NAND driver that adds bounds checking to the metadata parser.
  • Restrict the NAND mounting interface to trusted users or processes to prevent unauthorized images from being loaded.
  • If no patch is available, place the NAND mounting operation in a sandbox or monitor for anomalous memory writes and treat any suspect activity as a potential exploit.

Generated by OpenCVE AI on September 29, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unbounded Out-of-Bounds Write in Eclipse ThreadX LevelX NAND Driver Enables Control-Flow Hijack

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)
Weaknesses CWE-1284
CWE-787
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:25:33.808Z

Reserved: 2026-09-29T16:15:23.917Z

Link: CVE-2026-102730

cve-icon Vulnrichment

Updated: 2026-09-29T18:24:42.538Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:12.770

Modified: 2026-09-29T19:17:23.523

Link: CVE-2026-102730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-787

    Out-of-bounds Write