IcmpV6 Option Validation Flaw in NetX Duo by Eclipse
CVE-2026-102714
7.1HIGH
What is CVE-2026-102714?
The vulnerability in Eclipse's NetX Duo arises from an improper validation in the _nx_icmpv6_validate_options() function, which fails to examine potential trailing bytes during option processing. This oversight can lead to potential denial of service as the system enters a loop without yielding, freezing operations until a watchdog reset occurs. Additionally, the mismanagement of unsigned counters may lead to underflows, causing the process to access memory beyond allocated buffers. The outcome may compromise system stability and allow for unwanted memory manipulation. The flaw primarily affects how ICMPv6 options are parsed, posing a risk in network communications.
Affected Version(s)
NetX Duo 0 <= 6.5.1.202602
