`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer. | |
| Weaknesses | CWE-131 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-09-29T18:26:36.721Z
Reserved: 2026-09-29T16:15:23.083Z
Link: CVE-2026-102729
No data.
Status : Received
Published: 2026-09-29T18:17:12.620
Modified: 2026-09-29T18:17:12.620
Link: CVE-2026-102729
No data.
OpenCVE Enrichment
No data.