CVE-2026-102720
Awaiting Analysis Awaiting Analysis - Queue

Buffer Overflow in NetX DHCP Client

Vulnerability report for CVE-2026-102720, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1) { ... size = *(++data); /* data moves 1: type -> length byte */ data += size + 1; /* data moves size + 1 more */ i += size + 1; /* i moves only size + 1 */ } ``` A TLV option occupies size + 2 bytes. `data` is advanced by size + 2 in total, `i` by size + 1, so the offset falls one byte behind the real read position for every option the walk skips. After enough skipped options the check `i < length - 1` still holds while `data` is already past the end of the message, and the subsequent read of the type and length bytes comes from whatever follows. A single OFFER carrying a long run of skippable options is enough: ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x61b000000794 thread T5 #0 _nx_dhcp_search_buffer addons/dhcp/nxd_dhcp_client.c:7541 #1 _nx_dhcp_get_option_value addons/dhcp/nxd_dhcp_client.c:7082 0x61b000000794 is located 164 bytes to the right of 1648-byte region ``` A well formed OFFER through the same path is handled normally, the client records the offer and moves to REQUESTING, so the difference is the option layout rather than the harness. The read runs in the DHCP client thread while the client is still unconfigured, so it happens on every boot in reach of a hostile DHCP responder. The values read are used to configure the interface, which is how the disclosed bytes become observable. Advance `i` by size + 2, or derive the bound from `data` rather than keeping a second counter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap buffer overflow in a DHCP client implementation. The client's option parsing logic advances a pointer faster than a counter, causing it to read past the end of received DHCP messages. A malicious DHCP server can exploit this by sending crafted options to trigger out-of-bounds memory access.

Detection Guidance

This vulnerability involves a heap-buffer-overflow in a DHCP client due to improper bounds checking during option parsing. Detection requires monitoring for heap-buffer-overflow errors or crashes in DHCP client processes during system boot or network initialization. Check system logs for AddressSanitizer or similar memory error reports.

Impact Analysis

An attacker on the same local network could exploit this to read sensitive memory from the DHCP client process. This might expose configuration details or other process memory. The vulnerability triggers automatically on every system boot when a hostile DHCP responder is present.

Mitigation Strategies

Apply patches or updates from the DHCP client software vendor that fix the bounds checking issue. If no patch is available, restrict access to DHCP servers on your network to trusted sources only. Monitor vendor advisories for updates and consider disabling DHCP client services if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102720. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart