Out-of-Bounds Memory Disclosure in Network Protocol by Eclipse
CVE-2026-102712
8.8HIGH
What is CVE-2026-102712?
A vulnerability exists in the DTLS networking protocol where the parser improperly handles the session_id length during the initial ClientHello handshake. This flaw allows an unauthenticated peer to trigger an out-of-bounds read, leading to a potential disclosure of sensitive adjacent memory over the network. This disclosure occurs when the malicious input drives the read of up to 255 bytes, which are then echoed in the outgoing ServerHello response. Furthermore, the vulnerability is inherently exploitable upon the receipt of the first packet, compromising the affected system's security.
Affected Version(s)
NetX Duo 0 <= 6.5.1.202602
