PT-2026-102767 · Eclipse Foundation+1 · Eclipse Threadx Netx Duo+1
CVSS v4.0
5.3
Medium
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A heap-buffer-overflow occurs when a DHCP server or a malicious actor on the local area network responds to a DISCOVER message. The issue stems from an incorrect bound check during the option walk process, where a pointer and an offset are kept out of sync. Specifically, for every TLV (Type-Length-Value) option skipped, the offset falls one byte behind the actual read position. This allows the system to read approximately one kilobyte past the end of the received message if a long sequence of skippable options is provided in an OFFER message. This read operation occurs in the DHCP client thread during boot while the client is unconfigured, and the leaked bytes can be used to configure the interface, making the disclosed information observable. The flaw is located in the
nx dhcp search buffer() function, which is called by nx dhcp get option value().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Threadx Netx Duo
Netx Duo