---
id: CVE-2026-102714
title: >-
  `_nx_icmpv6_validate_options()` scans the option area with `while (length >
  2)` (`common/src/nx_icmpv6_validate_options.c:79`)
summary: >-
  `_nx_icmpv6_validate_options()` scans the option area with `while (length >
  2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves
  a one- or two-byte residue exits the loop with that tail unexamined; the
  residue is…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-125
  - CWE-191
  - CWE-835
  - CWE-1287
vendor: Eclipse Foundation
product: NetX Duo
affected:
  - netx_duo <= 6.5.1.202602
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:10.617'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102714'
references:
  - url: >-
      https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-39p4-p83c-58hr
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T18:42:35.813Z'
---

## Overview

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes.



Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls.



**Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one.



**Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case.



**One-byte residue.** The walker reads a two-byte option header, over-reading one byte.



During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
