CVE-2026-102729: Medium severity Microsoft Azure RTOS GUIX vulnerability

Published Sep 29, 2026
·
Updated

gxbinresthemeload() sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a GXTHEME and its tables into that zero-byte buffer.

Affected Software

1 affected component
Microsoft Azure RTOS GUIX

Event History

Sep 29, 2026
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What condition is required to trigger the out-of-bounds write?

gx_binres_theme_load() must be asked to load a theme ID that is equal to or greater than the theme count declared in the binary resource. In that case, it allocates a zero-byte buffer and then processes data beyond the theme table as though it were a valid theme header.

2

How can I determine whether my application is exposed?

Review calls to gx_binres_theme_load() and verify that the requested theme ID is validated against the theme count declared by the loaded resource. Applications that can request IDs outside that range can reach the vulnerable path.

3

What can be done if an update is not immediately available?

Ensure theme IDs are rejected unless they are below the theme count declared by the binary resource before gx_binres_theme_load() is called. Also avoid loading resources or accepting theme-selection inputs that can produce out-of-range IDs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203