CVE-2026-102729: Medium severity Microsoft Azure RTOS GUIX vulnerability
gxbinresthemeload() sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a GXTHEME and its tables into that zero-byte buffer.
Affected Software
Event History
Frequently Asked Questions
What condition is required to trigger the out-of-bounds write?
gx_binres_theme_load() must be asked to load a theme ID that is equal to or greater than the theme count declared in the binary resource. In that case, it allocates a zero-byte buffer and then processes data beyond the theme table as though it were a valid theme header.
How can I determine whether my application is exposed?
Review calls to gx_binres_theme_load() and verify that the requested theme ID is validated against the theme count declared by the loaded resource. Applications that can request IDs outside that range can reach the vulnerable path.
What can be done if an update is not immediately available?
Ensure theme IDs are rejected unless they are below the theme count declared by the binary resource before gx_binres_theme_load() is called. Also avoid loading resources or accepting theme-selection inputs that can produce out-of-range IDs.