PT-2026-102762 · Eclipse Foundation+1 · Netx Duo
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A flaw exists in the
nx icmpv6 validate options() function where it fails to examine a one- or two-byte residue at the end of an option area. This allows subsequent processing functions to re-walk the area and encounter attacker-controlled bytes, leading to three potential outcomes:- If a zero length byte is present, the handlers
nx icmpv6 process ra(),nx icmpv6 process ns(),nx icmpv6 process na(), andnx icmpv6 process redirect()enter an infinite loop. Since this occurs in the high-priority IP thread without yielding, the system hangs until a watchdog reset occurs. - If a non-zero length byte is present on a short residue, unsigned counters may underflow, causing the process to read past the packet buffer until a fault occurs or a zero length byte is encountered.
- If a one-byte residue exists, the walker over-reads one byte when reading a two-byte option header.
Additionally, during a runaway walk, bytes interpreted as a link-layer address option may be copied into the neighbor cache and used as a destination MAC, potentially leaking off-packet memory onto the link.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Infinite Loop
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netx Duo