VYPR

threadx

by Eclipse Threadx

CVEs (4)

  • CVE-2026-102710CriSep 29, 2026
    risk 0.60cvss —epss —

    Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global…

  • CVE-2026-102757HigSep 29, 2026
    risk 0.55cvss —epss —

    An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged…

  • CVE-2026-102709HigSep 29, 2026
    risk 0.55cvss —epss —

    Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled…

  • CVE-2026-102711MedSep 29, 2026
    risk 0.37cvss —epss —

    Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in…