---
id: CVE-2026-102715
title: >-
  Any host on the LAN can send two mDNS records and make the responder write
  past the end of its




  transmit packet.




  The string table stores each name in a slot rounded up to a multiple of four:




  ```c




  /* addons/mdns/nxd_mdns.c:1143…
summary: >-
  Any host on the LAN can send two mDNS records and make the responder write
  past the end of its




  transmit packet.




  The string table stores each name in a slot rounded up to a multiple of four:




  ```c




  /* addons/mdns/nxd_mdns.c:1143…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-787
vendor: Eclipse Foundation
product: eclipse-threadx/netxduo
affected:
  - eclipse-threadx/netxduo <= 6.5.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:10.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102715'
references:
  - url: >-
      https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2gf7-5224-5vrj
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T18:42:35.814Z'
---

## Overview

Any host on the LAN can send two mDNS records and make the responder write past the end of its



transmit packet.



The string table stores each name in a slot rounded up to a multiple of four:



```c



/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */



memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;



...



len = *((USHORT*)(p - 2));           /* slot size, not string length */



if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)



```



The lookup that decides whether an incoming name is already stored compares the rounded slot size,



so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered



with the pointer to the first, and the record then carries a string up to three bytes longer than



the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only



bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.



Two PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names



whose lengths fall in the same bucket:



```



==87491==ERROR: AddressSanitizer: heap-buffer-overflow



WRITE of size 1 at 0x611000000124 thread T5

    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096
    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911


0x611000000124 is 0 bytes to the right of 228-byte region



```



The overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a



normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible



effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.



Compare the slot size against the stored string length before declaring a match, or keep the



string length in the slot header and return it to the caller so the encoder and the bound check



agree.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
