CVE-2026-102715

Source
https://cve.org/CVERecord?id=CVE-2026-102715
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102715.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102715
Aliases
  • GHSA-2gf7-5224-5vrj
Published
2026-09-29T17:42:35Z
Modified
2026-10-01T03:30:33Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet
Details

Any host on the LAN can send two mDNS records and make the responder write past the end of its

transmit packet.

The string table stores each name in a slot rounded up to a multiple of four:




/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */



memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;



...



len = *((USHORT*)(p - 2));           /* slot size, not string length */



if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)



The lookup that decides whether an incoming name is already stored compares the rounded slot size,

so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered

with the pointer to the first, and the record then carries a string up to three bytes longer than

the length the caller accounted for. _nx_mdns_packet_rr_add (nxd_mdns.c:8911) sizes its only

bound check from that stale length, and _nx_mdns_name_string_encode writes the real string.

Two PTR records are enough, both ordinary mDNS responses to a _http._tcp query, with owner names

whose lengths fall in the same bucket:




==87491==ERROR: AddressSanitizer: heap-buffer-overflow



WRITE of size 1 at 0x611000000124 thread T5

    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096
    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911


0x611000000124 is 0 bytes to the right of 228-byte region



The overflow is one to three bytes of attacker-influenced name data past nx_packet_data_end. In a

normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible

effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.

Compare the slot size against the stored string length before declaring a match, or keep the

string length in the slot header and return it to the caller so the encoder and the bound check

agree.

Database specific
{
    "cna_assigner":  "eclipse",
    "cwe_ids":  [
        "CWE-787"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102715.json"
}
References

Affected packages

Git / github.com/eclipse-threadx/netxduo

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-threadx/netxduo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "6.5.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v.*
v.6.4.4.202503_rel
v6.*
v6.0.1_rel
v6.0.2_rel
v6.0_rel
v6.1.10_rel
v6.1.11_rel
v6.1.12_rel
v6.1.2_rel
v6.1.3_rel
v6.1.4_rel
v6.1.5_rel
v6.1.6_rel
v6.1.7_rel
v6.1.8_rel
v6.1.9_rel
v6.1_rel
v6.2.0_rel
v6.2.1_rel
v6.3.0_rel
v6.4.0_rel
v6.4.1_rel
v6.4.2_rel
v6.4.3_rel
v6.4.4.202503a
v6.4.5.202504_rel
v6.5.0.202601_rel
v6.5.1.202602_rel

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102715.json"