CriticalVulnerability
CVE-2026-102730: Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-102730
- Published
- Record updated
Summary
Mounting an attacker-controlled NAND flash image through `lx_nand_flash_open()` triggers an unbounded out-of-bounds heap write in LevelX's NAND flash-translation-layer metadata parser. The write overwrites a driver function pointer in the control block, and a demonstrated control-flow hijack sets RIP to a full 8-byte attacker-chosen value, verified in registers. Two further out-of-bounds reads accompany it, all reproduced under ASan at HEAD `9f1cfdc`. The affected header notes that some portions were generated by Copilot (Sonnet 4.6), and the parser relies on an unchecked on-flash count.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database