Buffer Overflow Vulnerability in Eclipse ThreadX Guix Theme Management
CVE-2026-102729

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102729?

The gx_binres_theme_load() function in Eclipse ThreadX Guix encounters a critical flaw by allocating a theme buffer incorrectly, allowing for the possibility of a buffer overflow. When a non-existent theme ID is requested, the function attempts to access a null or zero-byte buffer, which can potentially lead to undefined behavior. This vulnerability could allow attackers to manipulate memory, potentially leading to arbitrary code execution or other detrimental impacts on system integrity.

Affected Version(s)

GUIX 0 <= 6.5.1.202602a

GUIX 6.5.2.202603

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

fdesbiens
.