Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.) | |
| Weaknesses | CWE-1284 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-09-29T18:25:33.808Z
Reserved: 2026-09-29T16:15:23.917Z
Link: CVE-2026-102730
No data.
Status : Received
Published: 2026-09-29T18:17:12.770
Modified: 2026-09-29T18:17:12.770
Link: CVE-2026-102730
No data.
OpenCVE Enrichment
No data.