CVE-2026-102711
Last modified
CVE-2026-102711 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded)..
Description
Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | `eclipse-threadx/threadx` (module manager / loadable-module loader) | current HEAD and prior (the `_txm_module_manager_*_load` APIs take no image length). |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102711?
How severe is CVE-2026-102711?
How do I fix CVE-2026-102711?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10269A security vulnerability has been detected in decolua 9route…6.3
- CVE-2026-102697Ollama versions 0.14.0 before 0.31.2 contain an incorrect au…7.8
- CVE-2026-10270A vulnerability was detected in D-Link DI-7001 MINI up to 19…7.5
- CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple …8.4
- CVE-2026-10271A flaw has been found in a4m4 Student-Management-System up t…6.3
- CVE-2026-102710Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MO…9.3
- CVE-2026-102712On the first DTLS ClientHello, the parser copies a device-cl…8.8
- CVE-2026-102713The TFTP server accepts a DATA datagram of any size. The dis…8.8
- CVE-2026-102714`_nx_icmpv6_validate_options()` scans the option area with `…7.1
- CVE-2026-102715Any host on the LAN can send two mDNS records and make the r…7.1
- CVE-2026-102716An unauthenticated client can drain the RTSP server's packet…8.7
- CVE-2026-102718hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNM…8.7
Are you affected by CVE-2026-102711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
