VulnSea

threadx vulnerabilities

CVEs whose affected-version data names the threadx package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-102757High· 8.5
1w ago

An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Modul…

An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Modul…

▾ TwilightEclipse Foundation · ThreadXEPSS 0.10%via NVD
CVE-2026-102709High· 8.4
1w ago

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently …

▾ TwilightEclipse Foundation · ThreadXEPSS 0.10%via NVD
CVE-2025-55080High· 7.1
11mo ago

In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.

In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.

▾ Twilighteclipse · threadxEPSS 0.14%via NVD
CVE-2025-55079Medium· 5.5
11mo ago

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher priority than expected…

▾ Sunliteclipse · threadxEPSS 0.17%via NVD
CVE-2025-55078Medium· 5.5
11mo ago

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying w…

▾ Sunliteclipse · threadxEPSS 0.17%via NVD
threadx vulnerabilities (CVEs) · VulnSea