{"id":"CVE-2026-102730","title":"Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the contro…","summary":"Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the contro…","severity":"high","cvss":8.6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-787","CWE-1284"],"vendor":"Eclipse Foundation","product":"eclipse-threadx/levelx(NAND driver)","affected":["eclipse-threadx_levelx_nand_driver HEAD `9f1cfdc` and prior; Finding 1 introduced by commit `47b2a17d`; Finding 2 is   the un-patched half of the Nov-2025 fix `0f7dd521`."],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:17:12.770","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102730","references":[{"url":"https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g","label":"emo@eclipse.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-29T18:24:34.920877Z"},"cvssSource":"cna","ingestedAt":"2026-09-29T18:42:35.819Z","slug":"CVE-2026-102730","body":"## Overview\n\nMounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states \"Some portions generated by Copilot (Sonnet 4.6)\" — an AI-generated parser with an unchecked on-flash count.)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}