CVE-2026-102758 (GCVE-0-2026-102758)

Vulnerability from cvelistv5 – Published: 2026-09-29 17:26 – Updated: 2026-09-30 20:42
VLAI
Summary
The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer. code: nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c ``` UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type, USHORT *tlv_tag_class, ULONG *tlv_length, const UCHAR **tlv_data, ULONG *header_length) { UINT current_index; USHORT current_tag; ULONG length; ULONG length_bytes; current_index = 0; current_tag = buffer[current_index]; /* <-- read before the bounds check */ if (*buffer_length < 1) { return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG); } ``` The remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 20:42 UTC
CWE
Impacted products
Vendor Product Version
Eclipse Foundation NetX Duo Affected: 0 , ≤ 6.5.1.202602 (custom)
Unaffected: 6.5.2.202603
Create a notification for this product.
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 7.5,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-102758",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T20:42:14.455455Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T20:42:39.497Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "NetX Duo",
          "product": "NetX Duo",
          "vendor": "Eclipse Foundation",
          "versions": [
            {
              "lessThanOrEqual": "6.5.1.202602",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "6.5.2.202603"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "tinic"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\u003c/p\u003e\u003cp\u003eThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\u003c/p\u003e\u003cp\u003ecode:\u003c/p\u003e\u003cp\u003enx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\u003c/p\u003e\u003cp\u003e```\u003c/p\u003e\u003cp\u003eUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\u003c/p\u003e\u003ccode\u003e                                          USHORT *tlv_tag_class, ULONG *tlv_length,\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e                                          const UCHAR **tlv_data, ULONG *header_length)\u003c/code\u003e\u003cbr\u003e\u003cp\u003e{\u003c/p\u003e\u003cp\u003eUINT   current_index;\u003c/p\u003e\u003cp\u003eUSHORT current_tag;\u003c/p\u003e\u003cp\u003eULONG  length;\u003c/p\u003e\u003cp\u003eULONG  length_bytes;\u003c/p\u003e\u003ccode\u003e    current_index = 0;\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    current_tag = buffer[current_index];      /* \u0026lt;-- read before the bounds check */\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    if (*buffer_length \u0026lt; 1)\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    {\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    }\u003c/code\u003e\u003cbr\u003e\u003cp\u003e```\u003c/p\u003e\u003cp\u003eThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u0026gt; 4 || length_bytes \u0026gt; *buffer_length` before its read loop, the decoded value is checked against `length \u0026gt; *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u0026lt; 1` guard. The tag read is the only load placed ahead of its check.\u003c/p\u003e"
            }
          ],
          "value": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* \u003c-- read before the bounds check */\n    if (*buffer_length \u003c 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-126",
              "description": "CWE-126 Buffer Over-read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T17:26:44.424Z",
        "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "shortName": "eclipse"
      },
      "references": [
        {
          "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
    "assignerShortName": "eclipse",
    "cveId": "CVE-2026-102758",
    "datePublished": "2026-09-29T17:26:44.424Z",
    "dateReserved": "2026-09-29T16:21:58.057Z",
    "dateUpdated": "2026-09-30T20:42:39.497Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-102758",
      "date": "2026-10-01",
      "epss": "0.00173",
      "percentile": "0.06037"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "packageName": "NetX Duo",
                "product": "NetX Duo",
                "vendor": "Eclipse Foundation",
                "versions": [
                  {
                    "lessThanOrEqual": "6.5.1.202602",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "status": "unaffected",
                    "version": "6.5.2.202603"
                  }
                ]
              }
            ],
            "source": "emo@eclipse.org"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* \u003c-- read before the bounds check */\n    if (*buffer_length \u003c 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check."
          }
        ],
        "id": "CVE-2026-102758",
        "lastModified": "2026-09-30T21:17:05.347",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 3.6,
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ],
          "ssvcV203": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "ssvcData": {
                "id": "CVE-2026-102758",
                "options": [
                  {
                    "exploitation": "none"
                  },
                  {
                    "automatable": "yes"
                  },
                  {
                    "technicalImpact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T20:42:14.455455Z",
                "version": "2.0.3"
              }
            }
          ]
        },
        "published": "2026-09-29T18:17:13.047",
        "references": [
          {
            "source": "emo@eclipse.org",
            "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"
          }
        ],
        "sourceIdentifier": "emo@eclipse.org",
        "vulnStatus": "Awaiting Analysis",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-126"
              }
            ],
            "source": "emo@eclipse.org",
            "type": "Secondary"
          }
        ]
      }
    },
    "vulnrichment": {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102758",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T20:42:14.455455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:42:35.929Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "NetX Duo",
              "product": "NetX Duo",
              "vendor": "Eclipse Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "6.5.1.202602",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "6.5.2.202603"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "tinic"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\u003c/p\u003e\u003cp\u003eThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\u003c/p\u003e\u003cp\u003ecode:\u003c/p\u003e\u003cp\u003enx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\u003c/p\u003e\u003cp\u003e```\u003c/p\u003e\u003cp\u003eUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\u003c/p\u003e\u003ccode\u003e                                          USHORT *tlv_tag_class, ULONG *tlv_length,\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e                                          const UCHAR **tlv_data, ULONG *header_length)\u003c/code\u003e\u003cbr\u003e\u003cp\u003e{\u003c/p\u003e\u003cp\u003eUINT   current_index;\u003c/p\u003e\u003cp\u003eUSHORT current_tag;\u003c/p\u003e\u003cp\u003eULONG  length;\u003c/p\u003e\u003cp\u003eULONG  length_bytes;\u003c/p\u003e\u003ccode\u003e    current_index = 0;\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    current_tag = buffer[current_index];      /* \u0026lt;-- read before the bounds check */\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    if (*buffer_length \u0026lt; 1)\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    {\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\u003c/code\u003e\u003cbr\u003e\u003ccode\u003e    }\u003c/code\u003e\u003cbr\u003e\u003cp\u003e```\u003c/p\u003e\u003cp\u003eThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u0026gt; 4 || length_bytes \u0026gt; *buffer_length` before its read loop, the decoded value is checked against `length \u0026gt; *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u0026lt; 1` guard. The tag read is the only load placed ahead of its check.\u003c/p\u003e"
                }
              ],
              "value": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* \u003c-- read before the bounds check */\n    if (*buffer_length \u003c 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-126",
                  "description": "CWE-126 Buffer Over-read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:26:44.424Z",
            "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
            "shortName": "eclipse"
          },
          "references": [
            {
              "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "assignerShortName": "eclipse",
        "cveId": "CVE-2026-102758",
        "datePublished": "2026-09-29T17:26:44.424Z",
        "dateReserved": "2026-09-29T16:21:58.057Z",
        "dateUpdated": "2026-09-30T20:42:39.497Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…