Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-103416: NetX Duo may overwrite memory during TLS 1.3 handshake

CVE-2026-103416 · published 3 days ago
Summary

The NetX Duo network stack in Eclipse ThreadX (version 6.5.1.202602) can write data past the end of a buffer when processing a TLS 1.3 handshake message that is larger than expected. A malicious server could cause this before the client checks the server's certificate, potentially corrupting the program's internal data. Update to a version that fixes the buffer handling or apply the vendor's patch to prevent the overflow.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
eclipse foundation eclipse threadx - netx duo <= 6.5.1.202602
Original advisory text
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest...
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-787Out-of-bounds Write
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-103416 · MITRE
Track software like this
Free during beta