Unbounded Out-of-Bounds Heap Write in LevelX NAND Flash-Translation Layer
CVE-2026-102730
8.6HIGH
What is CVE-2026-102730?
An attacker can exploit a flaw in LevelX's NAND flash-translation-layer metadata parser, allowing for an unbounded out-of-bounds heap write. This results in the potential for an attacker to control function pointers within the driver’s control block, which may lead to arbitrary code execution through control-flow hijacking. The flaw is attributed to improper handling of NAND flash images, which can result in critical data being overwritten. There are additional implications highlighted by accompanying out-of-bounds read vulnerabilities, compounding the security risks.
Affected Version(s)
eclipse-threadx/levelx(NAND driver) HEAD `9f1cfdc` and prior; Finding 1 introduced by commit `47b2a17d`; Finding 2 is the un-patched half of the Nov-2025 fix `0f7dd521`.
