CVE-2026-102714
Last modified
CVE-2026-102714 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`.
Description
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | NetX Duo | <= 6.5.1.202602 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102714?
How severe is CVE-2026-102714?
How do I fix CVE-2026-102714?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple …8.4
- CVE-2026-10271A flaw has been found in a4m4 Student-Management-System up t…6.3
- CVE-2026-102710Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MO…9.3
- CVE-2026-102711Two issues in the ThreadX loadable-module loader, reached wh…5.7
- CVE-2026-102712On the first DTLS ClientHello, the parser copies a device-cl…8.8
- CVE-2026-102713The TFTP server accepts a DATA datagram of any size. The dis…8.8
- CVE-2026-102715Any host on the LAN can send two mDNS records and make the r…7.1
- CVE-2026-102716An unauthenticated client can drain the RTSP server's packet…8.7
- CVE-2026-102718hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNM…8.7
- CVE-2026-102719Predictable DTLS HelloVerifyRequest Cookie in NetX Secure6.3
- CVE-2026-10272A vulnerability has been found in a4m4 Student-Management-Sy…6.5
- CVE-2026-102720A DHCP server, or anyone on the LAN who answers a DISCOVER f…5.3
Are you affected by CVE-2026-102714?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
