CVE-2026-102714: CWE-125 Out-of-bounds Read in Eclipse Foundation NetX Duo
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.
AI Analysis
Technical Summary
The vulnerability exists in the function _nx_icmpv6_validate_options() in NetX Duo, which scans ICMPv6 option areas but exits early if a one- or two-byte residue remains unexamined. This residue is then re-processed by various ICMPv6 handlers without proper length checks, leading to three main issues: infinite loops when a zero-length byte is encountered, unsigned integer underflows causing reads beyond packet buffers, and one-byte over-reads of option headers. The infinite loop occurs in the highest-priority IP thread, causing system hangs until watchdog resets. Additionally, memory beyond packet boundaries can be copied into the neighbor cache and used as MAC addresses, potentially causing network corruption. These behaviors were confirmed by code inspection.
Potential Impact
Exploitation can cause denial of service through infinite loops that hang the system until a watchdog reset occurs. Memory safety violations include out-of-bounds reads and copying of off-packet memory into network structures, which may lead to undefined behavior or network corruption. The vulnerability does not require privileges or user interaction and can be triggered remotely via crafted ICMPv6 packets over an adjacent network. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, network administrators should consider filtering or blocking suspicious ICMPv6 traffic from untrusted sources to reduce exposure. Monitoring for unusual system hangs or watchdog resets may help detect exploitation attempts. Avoid relying on generic mitigations as the vulnerability specifically involves ICMPv6 option parsing.
CVE-2026-102714: CWE-125 Out-of-bounds Read in Eclipse Foundation NetX Duo
Description
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.
CVSS v4.0
Score 7.1high
Affected software
Eclipse Foundation
NetX Duo
pkg:github/eclipse-threadx/netxduoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the function _nx_icmpv6_validate_options() in NetX Duo, which scans ICMPv6 option areas but exits early if a one- or two-byte residue remains unexamined. This residue is then re-processed by various ICMPv6 handlers without proper length checks, leading to three main issues: infinite loops when a zero-length byte is encountered, unsigned integer underflows causing reads beyond packet buffers, and one-byte over-reads of option headers. The infinite loop occurs in the highest-priority IP thread, causing system hangs until watchdog resets. Additionally, memory beyond packet boundaries can be copied into the neighbor cache and used as MAC addresses, potentially causing network corruption. These behaviors were confirmed by code inspection.
Potential Impact
Exploitation can cause denial of service through infinite loops that hang the system until a watchdog reset occurs. Memory safety violations include out-of-bounds reads and copying of off-packet memory into network structures, which may lead to undefined behavior or network corruption. The vulnerability does not require privileges or user interaction and can be triggered remotely via crafted ICMPv6 packets over an adjacent network. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, network administrators should consider filtering or blocking suspicious ICMPv6 traffic from untrusted sources to reduce exposure. Monitoring for unusual system hangs or watchdog resets may help detect exploitation attempts. Avoid relying on generic mitigations as the vulnerability specifically involves ICMPv6 option parsing.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-09-29T16:15:10.456Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbfcc9107c4a03cbb2801a
Added to database: 09/29/2026, 18:00:41 UTC
Last enriched: 09/29/2026, 18:01:37 UTC
Last updated: 09/29/2026, 18:51:53 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.