CVE-2026-102716
An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests
that carry a Session header the parser cannot convert.
The Session branch returns the raw NetX error code instead of an RTSP status code:
```c
/* addons/rtsp/nx_rtsp_server.c:2754 */
if (status)
```
Every other branch of the same function maps its failure to an RTSP status first. The CSeq branch
eighteen lines earlier does exactly that (line 2736 returns NX_RTSP_STATUS_CODE_BAD_REQUEST). The
raw code then reaches `_nx_rtsp_server_error_response_send` (nx_rtsp_server.c:1234), which does not
recognise it, takes a path that returns without releasing the response packet it already allocated,
Leer descripción completaMostrar menos
and the block never goes back to the pool.
Six requests with an empty Session header against a 22 packet pool:
```
valid requests: after request 6: pool available = 21, AFTER = 22 / 22
malformed requests: after request 6: pool available = 16, AFTER = 17 / 22
```
One block per request, not returned when the client disconnects. Twenty six requests take the pool
to zero and the server starts failing allocations, after which it serves nobody. If the pool is
shared with the rest of the application, as it is in the shipped sample, the rest of the stack
stops with it.
Convert the `_nx_utility_string_to_uint` failure in the Session branch into
NX_RTSP_STATUS_CODE_BAD_REQUEST the way the CSeq branch does, and release the response packet on
every exit path of `_nx_rtsp_server_error_response_send`.
Detalles técnicos trazas, registros y código del informe original
status = _nx_utility_string_to_uint(field_value_ptr, field_value_length, &session_id);
{
return(status); /* NX_INVALID_PARAMETERS / NX_SIZE_ERROR / NX_OVERFLOW */
}CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Cliente no autenticado agota pool de paquetes RTSP (DoS) enviando requests malformados con Session header inválido, causando fallo de asignaciones y parada del servidor (CWE-401: memory leak).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-401
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-102716",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-102716",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-29T18:40:53.878601Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"vendor": "Eclipse Foundation",
"product": "eclipse-threadx/netxduo",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "6.5.1"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-29T18:17:10.943",
"references": [
{
"url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-q462-246c-x3jc",
"source": "emo@eclipse.org"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests\n\n\n\nthat carry a Session header the parser cannot convert.\n\n\n\nThe Session branch returns the raw NetX error code instead of an RTSP status code:\n\n\n\n```c\n\n\n\n/* addons/rtsp/nx_rtsp_server.c:2754 */\n\n\n\nstatus = _nx_utility_string_to_uint(field_value_ptr, field_value_length, &session_id);\n\n\n\nif (status)\n\n\n\n{\n\n return(status); /* NX_INVALID_PARAMETERS / NX_SIZE_ERROR / NX_OVERFLOW */\n\n\n}\n\n\n\n```\n\n\n\nEvery other branch of the same function maps its failure to an RTSP status first. The CSeq branch\n\n\n\neighteen lines earlier does exactly that (line 2736 returns NX_RTSP_STATUS_CODE_BAD_REQUEST). The\n\n\n\nraw code then reaches `_nx_rtsp_server_error_response_send` (nx_rtsp_server.c:1234), which does not\n\n\n\nrecognise it, takes a path that returns without releasing the response packet it already allocated,\n\n\n\nand the block never goes back to the pool.\n\n\n\nSix requests with an empty Session header against a 22 packet pool:\n\n\n\n```\n\n\n\nvalid requests: after request 6: pool available = 21, AFTER = 22 / 22\n\n\n\nmalformed requests: after request 6: pool available = 16, AFTER = 17 / 22\n\n\n\n```\n\n\n\nOne block per request, not returned when the client disconnects. Twenty six requests take the pool\n\n\n\nto zero and the server starts failing allocations, after which it serves nobody. If the pool is\n\n\n\nshared with the rest of the application, as it is in the shipped sample, the rest of the stack\n\n\n\nstops with it.\n\n\n\nConvert the `_nx_utility_string_to_uint` failure in the Session branch into\n\n\n\nNX_RTSP_STATUS_CODE_BAD_REQUEST the way the CSeq branch does, and release the response packet on\n\n\n\nevery exit path of `_nx_rtsp_server_error_response_send`."
}
],
"lastModified": "2026-09-29T19:17:20.780",
"sourceIdentifier": "emo@eclipse.org"
}