Heap Out-of-Bounds Read and Control Flow Integrity Issue in ThreadX
CVE-2026-102711

5.6MEDIUM

What is CVE-2026-102711?

The vulnerability affects ThreadX loadable-module loader, potentially allowing an attacker to exploit a heap out-of-bounds read through the _txm_module_manager_memory_load and _txm_module_manager_in_place_load APIs. These APIs utilize a base pointer without a defined image length, enabling the attacker to manipulate size and offset fields in TXM_MODULE_PREAMBLE. This can lead to the leakage of sensitive information via memory reads. Additionally, there is a control flow integrity issue where the lack of preamble checksum verification exposes the system to potential exploits leveraging untrusted module callbacks. Users are advised to apply the necessary updates to safeguard their systems.

Affected Version(s)

`eclipse-threadx/threadx` (module manager / loadable-module loader) current HEAD and prior (the `_txm_module_manager_*_load` APIs take no image length).

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adawn0106
.