CVE-2026-102711

Summary

Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via _txm_module_manager_memory_load / _txm_module_manager_in_place_load — APIs that take ONLY a base pointer, no image length, so every size/offset field in TXM_MODULE_PREAMBLE is fully attacker-trusted: (1) a heap OOB read (code_size trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as code_start + preamble_offset with only a != 0 check, and the preamble checksum never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).

Affected Software

VendorProductVersion RangeStatus
Eclipse Foundationeclipse-threadx/threadx (module manager / loadable-module loader)current HEAD and prior (the txm_module_manager*_load APIs take no image length).affected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds Read
  • CWE-345: CWE-345 Insufficient Verification of Data Authenticity
  • CWE-1284: CWE-1284 Improper Validation of Specified Quantity in Input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References