« Volver al listado

CVE-2026-102715

Estado: Pendiente de análisisAlta (7.1)—

Any host on the LAN can send two mDNS records and make the responder write past the end of its

transmit packet.

The string table stores each name in a slot rounded up to a multiple of four:

```c

/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */

...

len = *((USHORT*)(p - 2)); /* slot size, not string length */

if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)

```

The lookup that decides whether an incoming name is already stored compares the rounded slot size,

so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered

with the pointer to the first, and the record then carries a string up to three bytes longer than

Leer descripción completaMostrar menos

the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only

bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.

Two PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names

whose lengths fall in the same bucket:

```

0x611000000124 is 0 bytes to the right of 228-byte region

```

The overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a

normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible

effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.

Compare the slot size against the stored string length before declaring a match, or keep the

string length in the slot header and return it to the caller so the encoder and the bound check

agree.

Detalles técnicos trazas, registros y código del informe original
memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;

==87491==ERROR: AddressSanitizer: heap-buffer-overflow

WRITE of size 1 at 0x611000000124 thread T5

    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096
    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Buffer overflow en mDNS (AV:A, sin privilegios) permite corrupción de paquetes adyacentes. El atacante controla datos de nombre escritos más allá del límite, afectando integridad de datos y disponibilidad del servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-102715",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-102715",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-29T18:41:47.412014Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "emo@eclipse.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "emo@eclipse.org",
      "affectedData": [
        {
          "vendor": "Eclipse Foundation",
          "product": "eclipse-threadx/netxduo",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "6.5.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-29T18:17:10.780",
  "references": [
    {
      "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2gf7-5224-5vrj",
      "source": "emo@eclipse.org"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "emo@eclipse.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Any host on the LAN can send two mDNS records and make the responder write past the end of its\n\n\n\ntransmit packet.\n\n\n\nThe string table stores each name in a slot rounded up to a multiple of four:\n\n\n\n```c\n\n\n\n/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */\n\n\n\nmemory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;\n\n\n\n...\n\n\n\nlen = *((USHORT*)(p - 2));           /* slot size, not string length */\n\n\n\nif ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)\n\n\n\n```\n\n\n\nThe lookup that decides whether an incoming name is already stored compares the rounded slot size,\n\n\n\nso names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered\n\n\n\nwith the pointer to the first, and the record then carries a string up to three bytes longer than\n\n\n\nthe length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only\n\n\n\nbound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.\n\n\n\nTwo PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names\n\n\n\nwhose lengths fall in the same bucket:\n\n\n\n```\n\n\n\n==87491==ERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nWRITE of size 1 at 0x611000000124 thread T5\n\n    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096\n    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911\n\n\n0x611000000124 is 0 bytes to the right of 228-byte region\n\n\n\n```\n\n\n\nThe overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a\n\n\n\nnormal pool that lands in the next packet in the same pool rather than in a redzone, so the visible\n\n\n\neffect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.\n\n\n\nCompare the slot size against the stored string length before declaring a match, or keep the\n\n\n\nstring length in the slot header and return it to the caller so the encoder and the bound check\n\n\n\nagree."
    }
  ],
  "lastModified": "2026-09-29T19:17:20.627",
  "sourceIdentifier": "emo@eclipse.org"
}