PT-2026-102763 · Eclipse Foundation+1 · Eclipse Threadx Netx Duo+1
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A heap-buffer-overflow occurs when a host on the local area network sends two mDNS records with owner names whose lengths fall into the same rounded slot size bucket (for example, names between 12 and 15 characters). The system incorrectly matches a second name to an existing slot based on the rounded size rather than the actual string length. Consequently, the
nx mdns packet rr add() function performs a bound check using a stale length, while the nx mdns name string encode() function writes the actual, longer string. This results in one to three bytes of attacker-influenced data being written past the nx packet data end boundary, potentially corrupting neighboring packets or the pool free list.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Threadx Netx Duo
Netx Duo