Skip to main content

CVE-2026-102714: CWE-125 Out-of-bounds Read in Eclipse Foundation NetX Duo

0
High
Published: 09/29/2026 (09/29/2026, 17:41:28 UTC)
Source: CVE Database V5
Vendor/Project: Eclipse Foundation
Product: NetX Duo

Description

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.

CVSS v4.0

Score 7.1high

Attack Vector
Adjacent Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected software

Eclipse Foundation

NetX Duo

Affected versions
>=0 <=6.5.1.202602
GitHub Actionsmore threats →ai
eclipse-threadx/netxduo
pkg:github/eclipse-threadx/netxduo
Affected versions
<=6.5.1.202602

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 18:01:37 UTC

Technical Analysis

The vulnerability exists in the function _nx_icmpv6_validate_options() in NetX Duo, which scans ICMPv6 option areas but exits early if a one- or two-byte residue remains unexamined. This residue is then re-processed by various ICMPv6 handlers without proper length checks, leading to three main issues: infinite loops when a zero-length byte is encountered, unsigned integer underflows causing reads beyond packet buffers, and one-byte over-reads of option headers. The infinite loop occurs in the highest-priority IP thread, causing system hangs until watchdog resets. Additionally, memory beyond packet boundaries can be copied into the neighbor cache and used as MAC addresses, potentially causing network corruption. These behaviors were confirmed by code inspection.

Potential Impact

Exploitation can cause denial of service through infinite loops that hang the system until a watchdog reset occurs. Memory safety violations include out-of-bounds reads and copying of off-packet memory into network structures, which may lead to undefined behavior or network corruption. The vulnerability does not require privileges or user interaction and can be triggered remotely via crafted ICMPv6 packets over an adjacent network. No known exploits are reported in the wild.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, network administrators should consider filtering or blocking suspicious ICMPv6 traffic from untrusted sources to reduce exposure. Monitoring for unusual system hangs or watchdog resets may help detect exploitation attempts. Avoid relying on generic mitigations as the vulnerability specifically involves ICMPv6 option parsing.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
eclipse
Date Reserved
2026-09-29T16:15:10.456Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6abbfcc9107c4a03cbb2801a

Added to database: 09/29/2026, 18:00:41 UTC

Last enriched: 09/29/2026, 18:01:37 UTC

Last updated: 09/29/2026, 18:51:53 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses