{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "6.5.1"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "1a0e9e43a03e37ddecfb6b49e9b078d6e1803d05"
            }
          ],
          "repo": "https://github.com/eclipse-threadx/netxduo",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-2gf7-5224-5vrj"
  ],
  "database_specific": {
    "cna_assigner": "eclipse",
    "cwe_ids": [
      "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102715.json"
  },
  "details": "Any host on the LAN can send two mDNS records and make the responder write past the end of its\n\n\n\ntransmit packet.\n\n\n\nThe string table stores each name in a slot rounded up to a multiple of four:\n\n\n\n```c\n\n\n\n/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */\n\n\n\nmemory_len = ((memory_len \u0026 0xFFFFFFFC) + 8) \u0026 0xFFFFFFFF;\n\n\n\n...\n\n\n\nlen = *((USHORT*)(p - 2));           /* slot size, not string length */\n\n\n\nif ((len == memory_len) \u0026\u0026 ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)\n\n\n\n```\n\n\n\nThe lookup that decides whether an incoming name is already stored compares the rounded slot size,\n\n\n\nso names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered\n\n\n\nwith the pointer to the first, and the record then carries a string up to three bytes longer than\n\n\n\nthe length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only\n\n\n\nbound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.\n\n\n\nTwo PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names\n\n\n\nwhose lengths fall in the same bucket:\n\n\n\n```\n\n\n\n==87491==ERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nWRITE of size 1 at 0x611000000124 thread T5\n\n    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096\n    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911\n\n\n0x611000000124 is 0 bytes to the right of 228-byte region\n\n\n\n```\n\n\n\nThe overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a\n\n\n\nnormal pool that lands in the next packet in the same pool rather than in a redzone, so the visible\n\n\n\neffect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.\n\n\n\nCompare the slot size against the stored string length before declaring a match, or keep the\n\n\n\nstring length in the slot header and return it to the caller so the encoder and the bound check\n\n\n\nagree.",
  "id": "CVE-2026-102715",
  "modified": "2026-10-01T03:30:33.288652041Z",
  "published": "2026-09-29T17:42:35.719Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102715.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2gf7-5224-5vrj"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102715"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet"
}