{"data":{"id":"b44b94f2-d72c-440e-804d-e4f59a18a576","title":"CVE-2026-102730: Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap…","summary":"Mounting an attacker-controlled NAND flash image through `lx_nand_flash_open()` triggers an unbounded out-of-bounds heap write in LevelX's NAND flash-translation-layer metadata parser. The write overwrites a driver function pointer in the control block, and a demonstrated control-flow hijack sets RIP to a full 8-byte attacker-chosen value, verified in registers. Two further out-of-bounds reads accompany it, all reproduced under ASan at HEAD `9f1cfdc`. The affected header notes that some portions were generated by Copilot (Sonnet 4.6), and the parser relies on an unchecked on-flash count.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102730","publishedAt":"2026-09-29T18:17:12.770Z","cveId":"CVE-2026-102730","cweIds":["CWE-787","CWE-1284"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Copilot (Sonnet 4.6)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00117,"epssCheckedAt":"2026-10-10T02:56:18.802Z","kevDateAdded":null,"advisoryAliases":["GHSA-g54v-9g2q-gvrg"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:07.189Z","patchAvailable":null,"disclosureDate":"2026-09-29T18:17:12.770Z","capecIds":["CAPEC-100"],"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.6,"researchCategory":null,"atlasIds":null}}