PT-2026-102762 · Eclipse Foundation+1 · Netx Duo

·

CVE-2026-102714

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A flaw exists in the nx icmpv6 validate options() function where it fails to examine a one- or two-byte residue at the end of an option area. This allows subsequent processing functions to re-walk the area and encounter attacker-controlled bytes, leading to three potential outcomes:
  1. If a zero length byte is present, the handlers nx icmpv6 process ra(), nx icmpv6 process ns(), nx icmpv6 process na(), and nx icmpv6 process redirect() enter an infinite loop. Since this occurs in the high-priority IP thread without yielding, the system hangs until a watchdog reset occurs.
  2. If a non-zero length byte is present on a short residue, unsigned counters may underflow, causing the process to read past the packet buffer until a fault occurs or a zero length byte is encountered.
  3. If a one-byte residue exists, the walker over-reads one byte when reading a two-byte option header.
Additionally, during a runaway walk, bytes interpreted as a link-layer address option may be copied into the neighbor cache and used as a destination MAC, potentially leaking off-packet memory onto the link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102714
GHSA-39P4-P83C-58HR

Affected Products

Netx Duo