---
id: CVE-2026-102730
title: >-
  Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`)
  triggers an unbounded out-of-bounds heap **write** in LevelX's NAND
  flash-translation-layer metadata parser that overwrites a driver function
  pointer in the contro…
summary: >-
  Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`)
  triggers an unbounded out-of-bounds heap **write** in LevelX's NAND
  flash-translation-layer metadata parser that overwrites a driver function
  pointer in the contro…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-787
  - CWE-1284
vendor: Eclipse Foundation
product: eclipse-threadx/levelx(NAND driver)
affected:
  - >-
    eclipse-threadx_levelx_nand_driver HEAD `9f1cfdc` and prior; Finding 1
    introduced by commit `47b2a17d`; Finding 2 is   the un-patched half of the
    Nov-2025 fix `0f7dd521`.
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:12.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102730'
references:
  - url: >-
      https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T18:24:34.920877Z'
cvssSource: cna
ingestedAt: '2026-09-29T18:42:35.819Z'
---

## Overview

Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
