{"id":"CVE-2026-102730","published":"2026-09-29T18:17:12.770","lastModified":"2026-09-29T19:17:23.523","description":"Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states \"Some portions generated by Copilot (Sonnet 4.6)\" — an AI-generated parser with an unchecked on-flash count.)","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-787","CWE-1284"],"vendors":[],"products":[],"references":[{"url":"https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g","tags":[]}],"exploitRefs":[{"url":"https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g","tags":[]}],"hasPoc":true,"ai":null}