CVE-2026-102730
Last modified
CVE-2026-102730 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads.
Description
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | eclipse-threadx/levelx(NAND driver) | HEAD `9f1cfdc` and prior; Finding 1 introduced by commit `47b2a17d`; Finding 2 is the un-patched half of the Nov-2025 fix `0f7dd521`. |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102730?
How severe is CVE-2026-102730?
How do I fix CVE-2026-102730?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102725Out-of-bounds Read from Unvalidated MSRP Attribute List Leng…6
- CVE-2026-102726Unbounded PPP IPCP Option Parsing Causes a Worker Stall and …6
- CVE-2026-102727FTP Passive Data Connection Not Bound to the Authenticated C…6
- CVE-2026-102728Two client-side TLS/DTLS handshake parsers in NetX Secure re…
- CVE-2026-102729`gx_binres_theme_load()` sizes its theme buffer for the them…5.9
- CVE-2026-10273A vulnerability was found in php-censor up to 2.1.6. This af…7.3
- CVE-2026-10274A vulnerability was determined in indrasishbanerjee aem-mcp-…6.3
- CVE-2026-10275A flaw has been found in OpenSC up to 0.26.1. This affects t…5
- CVE-2026-102757An unprivileged, memory-protected ThreadX module can have th…8.5
- CVE-2026-102758The `_nx_secure_x509_asn1_tlv_block_parse()` function parses…
- CVE-2026-102759NetX Secure TLS accepts an empty application-data record wit…6.3
- CVE-2026-10276A vulnerability has been found in hekmon8 Jenkins-server-mcp…6.3
Are you affected by CVE-2026-102730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
