CVE-2026-102758
Awaiting Analysis Awaiting Analysis - Queue

Buffer Overread in NetX Secure X.509 Certificate Parsing

Vulnerability report for CVE-2026-102758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer. code: nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c ``` UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type, USHORT *tlv_tag_class, ULONG *tlv_length, const UCHAR **tlv_data, ULONG *header_length) { UINT current_index; USHORT current_tag; ULONG length; ULONG length_bytes; current_index = 0; current_tag = buffer[current_index]; /* <-- read before the bounds check */ if (*buffer_length < 1) { return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG); } ``` The remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netx secure *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow issue in the NetX Secure X.509 certificate parsing function. The function reads an ASN.1 tag byte from a buffer before verifying the buffer has at least one byte available. When the buffer length is zero, it still reads one byte past the end, causing a read out of bounds.

Detection Guidance

This vulnerability involves a buffer over-read in NetX Secure's X.509 certificate parsing. Detection requires analyzing network traffic for malformed TLS handshakes or inspecting system logs for crashes during certificate validation. No specific commands are provided in the context.

Impact Analysis

This could allow an attacker to cause a denial of service or potentially execute arbitrary code by sending a maliciously crafted certificate during a TLS handshake. It affects systems using NetX Secure for X.509 certificate validation.

Mitigation Strategies

Apply patches from the vendor if available. Disable TLS handshakes with untrusted peers until patched. Monitor for crashes in NetX Secure components. The vulnerability allows remote code execution via crafted certificates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart