Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-103416: NetX Duo may overwrite memory during TLS 1.3 handshake
CVE-2026-103416 · published 3 days ago
Summary
The NetX Duo network stack in Eclipse ThreadX (version 6.5.1.202602) can write data past the end of a buffer when processing a TLS 1.3 handshake message that is larger than expected. A malicious server could cause this before the client checks the server's certificate, potentially corrupting the program's internal data. Update to a version that fixes the buffer handling or apply the vendor's patch to prevent the overflow.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse foundation | eclipse threadx - netx duo | <= 6.5.1.202602 |
Original advisory text
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest...
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-1034... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-103416 Vendor Advisory
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/356
- https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-4x76-j955-qh...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-787Out-of-bounds Write
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-103416 · NVD
CVE-2026-103416 · MITRE
CVE-2026-103416 · OSV
GHSA-4x76-j955-qhq2 · GHSA
Track software like this
Free during beta