Improper Handling of Parameters Affecting eclipse-threadx/threadx package, versions [,6.4.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ECLIPSETHREADXTHREADX-13553158
  • published15 Oct 2025
  • disclosed15 Oct 2025
  • creditSaxon Mark

Introduced: 15 Oct 2025

NewCVE-2025-55080  (opens in a new tab)
CWE-233  (opens in a new tab)

How to fix?

Upgrade eclipse-threadx/threadx to version 6.4.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Parameters via insufficient validation of syscall parameters when memory protection is enabled. An attacker can gain privileges or access/modify arbitrary memory locations, bypassing user-kernel isolation by supplying specially crafted obj_ptr pointer.

References

CVSS Base Scores

version 4.0
version 3.1