CVE-2026-102710
Last modified
CVE-2026-102710 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps. An invalid pointer faults the kernel (DoS).
Description
Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps. An invalid pointer faults the kernel (DoS). A pointer into the module's own code was observed running with kernel privilege (`CONTROL.nPRIV = 0`), confirmed at runtime with a register capture inside that code.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | eclipse-threadx/threadx | <= v6.5.1.202602a_rel |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102710?
How severe is CVE-2026-102710?
How do I fix CVE-2026-102710?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10268A weakness has been identified in janet-lang janet up to 1.4…3.3
- CVE-2026-10269A security vulnerability has been detected in decolua 9route…6.3
- CVE-2026-102697Ollama versions 0.14.0 before 0.31.2 contain an incorrect au…7.8
- CVE-2026-10270A vulnerability was detected in D-Link DI-7001 MINI up to 19…7.5
- CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple …8.4
- CVE-2026-10271A flaw has been found in a4m4 Student-Management-System up t…6.3
- CVE-2026-102711Two issues in the ThreadX loadable-module loader, reached wh…5.7
- CVE-2026-102712On the first DTLS ClientHello, the parser copies a device-cl…8.8
- CVE-2026-102713The TFTP server accepts a DATA datagram of any size. The dis…8.8
- CVE-2026-102714`_nx_icmpv6_validate_options()` scans the option area with `…7.1
- CVE-2026-102715Any host on the LAN can send two mDNS records and make the r…7.1
- CVE-2026-102716An unauthenticated client can drain the RTSP server's packet…8.7
Are you affected by CVE-2026-102710?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
