Eclipse

Threadx

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 29.09.2026 17:59:30
  • Zuletzt bearbeitet 29.09.2026 19:17:23

Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, givi...

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 17:46:23
  • Zuletzt bearbeitet 29.09.2026 19:17:21

A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ...

  • EPSS 0.25%
  • Veröffentlicht 29.09.2026 17:43:55
  • Zuletzt bearbeitet 29.09.2026 19:17:20

An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c ...

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 17:42:35
  • Zuletzt bearbeitet 29.09.2026 19:17:20

Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 114...

  • EPSS 0.08%
  • Veröffentlicht 29.09.2026 17:38:22
  • Zuletzt bearbeitet 29.09.2026 22:17:08

Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so e...

  • EPSS 0.1%
  • Veröffentlicht 29.09.2026 17:37:04
  • Zuletzt bearbeitet 30.09.2026 21:17:05

Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function p...

  • EPSS 0.1%
  • Veröffentlicht 29.09.2026 17:36:17
  • Zuletzt bearbeitet 30.09.2026 21:17:05

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences ...

  • EPSS 0.1%
  • Veröffentlicht 29.09.2026 17:24:54
  • Zuletzt bearbeitet 02.10.2026 13:17:20

An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager dec...

  • EPSS 0.11%
  • Veröffentlicht 27.01.2026 15:40:31
  • Zuletzt bearbeitet 02.04.2026 20:30:57

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter(). Specifically, the current code checks i...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 27.01.2026 15:34:47
  • Zuletzt bearbeitet 02.04.2026 20:28:48

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partition table, it recursively calls itself to mount the next logical partit...