PT-2026-53239 · Eclipse · Tinydtls

·

CVE-2026-9267

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Eclipse tinydtls versions prior to commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221
Description An out-of-bounds read occurs in the check server certificate() function when processing a Certificate handshake message. Unauthenticated attackers can trigger reads beyond valid buffer boundaries by providing a specific fragment length value. This is possible due to missing buffer length validation before uint24 reads, memcmp, and memcpy operations during DTLS epoch 0 on both client and server paths, which can lead to a denial of service on memory-constrained devices.
Recommendations Update to the version containing commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9267

Affected Products

Tinydtls