---
id: CVE-2026-102711
title: >-
  Two issues in the ThreadX loadable-module loader, reached when a device loads
  an attacker-controlled module object via `_txm_module_manager_memory_load` /
  `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no
  image…
summary: >-
  Two issues in the ThreadX loadable-module loader, reached when a device loads
  an attacker-controlled module object via `_txm_module_manager_memory_load` /
  `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no
  image…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-125
  - CWE-345
  - CWE-1284
vendor: Eclipse Foundation
product: '`eclipse-threadx/threadx` (module manager / loadable-module loader)'
affected:
  - >-
    eclipse-threadx_threadx_module_manager_loadable-module_loader current HEAD
    and prior (the `_txm_module_manager_*_load` APIs take no image length).
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:10.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102711'
references:
  - url: >-
      https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-f53h-37j4-mqxx
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T18:42:35.812Z'
---

## Overview

Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
