CVE-2026-102720: CWE-125 Out-of-bounds Read in Eclipse Foundation eclipse-threadx/netxduo
CVE-2026-102720 is an out-of-bounds read vulnerability in the DHCP client implementation of Eclipse Foundation's eclipse-threadx/netxduo. A malicious DHCP server or any LAN device responding first to a DHCP DISCOVER message can cause the client to read approximately one kilobyte beyond the end of a received DHCP message. This occurs due to incorrect bounds checking when parsing DHCP options, where the offset counter lags behind the actual data pointer, allowing reads past the message boundary. The vulnerability can be triggered during every boot when the client is unconfigured and exposed to a hostile DHCP responder.
AI Analysis
Technical Summary
The vulnerability arises from a mismatch in how the DHCP client code advances a pointer and an offset while parsing DHCP options. Specifically, the code increments the data pointer by size + 2 bytes for each option but only increments the offset counter by size + 1. This causes the offset to fall behind the pointer, allowing the loop condition to remain true while the pointer has already moved past the message end. Consequently, the client reads memory beyond the DHCP message buffer, leading to an out-of-bounds read (CWE-125). The issue manifests when a DHCP OFFER contains a long sequence of skippable options. The read occurs in the DHCP client thread during interface configuration, potentially exposing memory contents to the attacker.
Potential Impact
An attacker controlling a DHCP server or any device on the LAN that responds first to DHCP DISCOVER can exploit this vulnerability to cause the DHCP client to read memory beyond the intended buffer. This out-of-bounds read may disclose sensitive information from adjacent memory. The vulnerability occurs during network interface configuration on every boot when the client is unconfigured, increasing exposure. However, no code execution or denial of service is explicitly described. The CVSS 4.0 score is 5.3 (medium severity) reflecting local network attack vector, low complexity, no privileges required, no user interaction, and limited confidentiality and availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability can be mitigated by correcting the offset increment to match the pointer advancement (i.e., incrementing the offset by size + 2) or by deriving bounds checks directly from the data pointer rather than maintaining a separate offset counter. Until a patch is available, network administrators should consider restricting DHCP responses to trusted servers and monitoring for unusual DHCP traffic patterns. No official fix or patch link is provided in the current data.
CVE-2026-102720: CWE-125 Out-of-bounds Read in Eclipse Foundation eclipse-threadx/netxduo
Description
CVE-2026-102720 is an out-of-bounds read vulnerability in the DHCP client implementation of Eclipse Foundation's eclipse-threadx/netxduo. A malicious DHCP server or any LAN device responding first to a DHCP DISCOVER message can cause the client to read approximately one kilobyte beyond the end of a received DHCP message. This occurs due to incorrect bounds checking when parsing DHCP options, where the offset counter lags behind the actual data pointer, allowing reads past the message boundary. The vulnerability can be triggered during every boot when the client is unconfigured and exposed to a hostile DHCP responder.
CVSS v4.0
Score 5.3medium
Affected software
Eclipse Foundation
eclipse-threadx/netxduo
pkg:github/eclipse-threadx/netxduoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from a mismatch in how the DHCP client code advances a pointer and an offset while parsing DHCP options. Specifically, the code increments the data pointer by size + 2 bytes for each option but only increments the offset counter by size + 1. This causes the offset to fall behind the pointer, allowing the loop condition to remain true while the pointer has already moved past the message end. Consequently, the client reads memory beyond the DHCP message buffer, leading to an out-of-bounds read (CWE-125). The issue manifests when a DHCP OFFER contains a long sequence of skippable options. The read occurs in the DHCP client thread during interface configuration, potentially exposing memory contents to the attacker.
Potential Impact
An attacker controlling a DHCP server or any device on the LAN that responds first to DHCP DISCOVER can exploit this vulnerability to cause the DHCP client to read memory beyond the intended buffer. This out-of-bounds read may disclose sensitive information from adjacent memory. The vulnerability occurs during network interface configuration on every boot when the client is unconfigured, increasing exposure. However, no code execution or denial of service is explicitly described. The CVSS 4.0 score is 5.3 (medium severity) reflecting local network attack vector, low complexity, no privileges required, no user interaction, and limited confidentiality and availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability can be mitigated by correcting the offset increment to match the pointer advancement (i.e., incrementing the offset by size + 2) or by deriving bounds checks directly from the data pointer rather than maintaining a separate offset counter. Until a patch is available, network administrators should consider restricting DHCP responses to trusted servers and monitoring for unusual DHCP traffic patterns. No official fix or patch link is provided in the current data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-09-29T16:15:16.300Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbfcc9107c4a03cbb2801f
Added to database: 09/29/2026, 18:00:41 UTC
Last enriched: 09/29/2026, 18:02:03 UTC
Last updated: 09/29/2026, 18:04:57 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.