← All Advisories

CVE-2026-102709

Last refreshed2026-10-11

Status: UPDATED  |  Advisory ID: CVE-2026-102709

Key Details

CVECVE-2026-102709
CVSS Score / Version8.4 (High) / CVSS v4.0
Updated2026-09-30
Affected productseclipse ThreadX
Classified asCWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
eclipseThreadX
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material. (NVD)

What to Do

Monitor eclipse's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-102709
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-102709