Eclipse Foundation · Guix · CVE-2026-102729
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
The `gx binres theme load()` function incorrectly sizes its theme buffer for the requested theme and performs allocation even if the resource contains no theme with that specific ID. When a theme ID is provided that is at or beyond the theme count declared by the resource, a buffer of zero bytes is allocated. Subsequently, the load process reads beyond the end of the theme table, interprets the following data as a theme header, and writes a `GX THEME` and its associated tables into the zero-byte buffer.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.