Eclipse Foundation · Netx Duo · CVE-2026-102714
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
A flaw exists in the ` nx icmpv6 validate options()` function where it fails to examine a one- or two-byte residue at the end of an option area. This allows subsequent processing functions to re-walk the area and encounter attacker-controlled bytes, leading to three potential outcomes:
1. If a zero length byte is present, the handlers ` nx icmpv6 process ra()`, ` nx icmpv6 process ns()`, ` nx icmpv6 process na()`, and ` nx icmpv6 process redirect()` enter an infinite loop. Since this occurs in the high-priority IP thread without yielding, the system hangs until a watchdog reset occurs.
2. If a non-zero length byte is present on a short residue, unsigned counters may underflow, causing the process to read past the packet buffer until a fault occurs or a zero length byte is encountered.
3. If a one-byte residue exists, the walker over-reads one byte when reading a two-byte option header.
Additionally, during a runaway walk, bytes interpreted as a link-layer address option may be copied into the neighbor cache and used as a destination MAC, potentially leaking off-packet memory onto the link.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.