NULL Pointer Dereference in Eclipse ThreadX Network Stack by Azure
CVE-2026-102724

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102724?

A NULL pointer dereference vulnerability has been identified in the Eclipse ThreadX Network Stack, which occurs when evicting the sole MSRP attribute. This issue may lead to unexpected application behavior or crashes, potentially allowing attackers to disrupt service or execute unauthorized operations. It is recommended to update to the latest version to mitigate this risk.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wsparks-vc
.