CVE-2026-102714
Awaiting Analysis Awaiting Analysis - Queue

Integer Underflow in NetXDUO ICMPv6 Option Parsing

Vulnerability report for CVE-2026-102714, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever β€” `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow β€” `2 - 8` becomes `0xFFFFFFFA` β€” and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
azure networking *
azure icmpv6 *
azure neighbor_cache *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-1287 The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a function `_nx_icmpv6_validate_options()` that incorrectly validates ICMPv6 option areas. It exits early when a packet leaves a small residue of 1-2 bytes, which are not checked. Consumers then re-process this residue, leading to infinite loops or memory corruption depending on the residue's byte values.

Detection Guidance

This vulnerability involves a loop in ICMPv6 processing that can cause system hangs or crashes. Detection requires monitoring for abnormal ICMPv6 traffic patterns or system freezes. Check for high CPU usage in IP threads or watchdog resets. Use network monitoring tools to inspect ICMPv6 packets for malformed options or infinite loops.

Impact Analysis

An attacker could exploit this to cause a denial of service by triggering infinite loops in critical IP thread functions, halting the system until a watchdog reset. Memory corruption may also occur, potentially allowing unauthorized data access or manipulation of neighbor cache entries.

Mitigation Strategies

Disable ICMPv6 processing if not required. Apply patches from the vendor if available. Use firewalls to filter malformed ICMPv6 packets. Monitor network traffic for suspicious ICMPv6 activity that could trigger the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102714. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart