{"id":"CVE-2026-102711","title":"Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image…","summary":"Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image…","severity":"medium","cvss":5.6,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-125","CWE-345","CWE-1284"],"vendor":"Eclipse Foundation","product":"`eclipse-threadx/threadx` (module manager / loadable-module loader)","affected":["eclipse-threadx_threadx_module_manager_loadable-module_loader current HEAD and prior (the `_txm_module_manager_*_load` APIs take no image length)."],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:17:10.163","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102711","references":[{"url":"https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-f53h-37j4-mqxx","label":"emo@eclipse.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T18:42:35.812Z","slug":"CVE-2026-102711","body":"## Overview\n\nTwo issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}