Heap Out-of-Bounds Read and Control Flow Integrity Issue in ThreadX
CVE-2026-102711
What is CVE-2026-102711?
The vulnerability affects ThreadX loadable-module loader, potentially allowing an attacker to exploit a heap out-of-bounds read through the _txm_module_manager_memory_load and _txm_module_manager_in_place_load APIs. These APIs utilize a base pointer without a defined image length, enabling the attacker to manipulate size and offset fields in TXM_MODULE_PREAMBLE. This can lead to the leakage of sensitive information via memory reads. Additionally, there is a control flow integrity issue where the lack of preamble checksum verification exposes the system to potential exploits leveraging untrusted module callbacks. Users are advised to apply the necessary updates to safeguard their systems.
Affected Version(s)
`eclipse-threadx/threadx` (module manager / loadable-module loader) current HEAD and prior (the `_txm_module_manager_*_load` APIs take no image length).
