CVE-2026-103416
Received Received - Intake

Out-of-bounds Write in Eclipse ThreadX NetX Duo TLS 1.3

Vulnerability report for CVE-2026-103416, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Eclipse Foundation

Description

Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX DuoΒ 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Eclipse Foundation Eclipse ThreadX - NetX Duo 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103416 is an out-of-bounds write vulnerability in Eclipse ThreadX NetX Duo's TLS 1.3 handshake message cache. It occurs when a handshake message larger than a fixed 500-byte array is written, corrupting adjacent memory including critical pointers in the session control block. An attacker can exploit this by sending a malicious server response before certificate authentication completes, requiring no privileges or user interaction.

Detection Guidance

Detecting this vulnerability requires checking if your NetX Duo version is vulnerable (6.5.1.202602 or earlier) and monitoring for crashes or memory corruption during TLS 1.3 handshakes. Review logs for abnormal TLS handshake failures or memory access violations.

Impact Analysis

This vulnerability can lead to crashes, data corruption, or arbitrary code execution depending on memory layout and platform protections. Since it occurs during TLS 1.3 handshake before authentication, an attacker could potentially compromise the system without needing a valid server certificate.

Mitigation Strategies

Upgrade NetX Duo to version 6.5.2.202603 or later, which includes bounds checking and configurable cache size. If upgrading is not possible, disable TLS 1.3 as a workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103416. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart