Skip to content
CriticalVulnerability

CVE-2026-102730: Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap…

Identifier
CVE-2026-102730
Published
Record updated
View JSON

Summary

Mounting an attacker-controlled NAND flash image through `lx_nand_flash_open()` triggers an unbounded out-of-bounds heap write in LevelX's NAND flash-translation-layer metadata parser. The write overwrites a driver function pointer in the control block, and a demonstrated control-flow hijack sets RIP to a full 8-byte attacker-chosen value, verified in registers. Two further out-of-bounds reads accompany it, all reproduced under ASan at HEAD `9f1cfdc`. The affected header notes that some portions were generated by Copilot (Sonnet 4.6), and the parser relies on an unchecked on-flash count.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.