{"id":"CVE-2026-102721","details":"A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the\n\n\n\nreceived datagram.\n\n\n\nEach receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229,\n\n\n\n1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose\n\n\n\nonly limits are the destination buffer and a NUL byte:\n\n\n\n```c\n\n\n\n/* addons/tftp/nxd_tftp_client.c:1769 */\n\n\n\nfor (i = 0; (i \u003c (sizeof(tftp_client_ptr -\u003e nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++)\n\n\n\n```\n\n\n\nNothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no\n\n\n\nterminating NUL, which a server controls completely, walks the loop off the end of the packet until\n\n\n\nit happens to meet a zero byte or fills the 64 byte destination.\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1 at 0x60d0000000c8 thread T4\n\n    #0 _nxd_tftp_client_file_read  addons/tftp/nxd_tftp_client.c:1769\n\n\n0x60d0000000c8 is 0 bytes to the right of 136-byte region\n\n\n\n```\n\n\n\nThe open path has the same loop at :1327 and reports the same way. What is read lands in\n\n\n\n`nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent\n\n\n\npacket pool memory ends up in whatever the device does with the error text.\n\n\n\nAdd `(buffer_ptr \u003c packet_ptr -\u003e nx_packet_append_ptr)` to the loop condition in all three paths.","aliases":["GHSA-wvc9-5m9h-rvxc"],"modified":"2026-10-01T03:30:22.004498082Z","published":"2026-09-29T17:47:12.769Z","database_specific":{"cna_assigner":"eclipse","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102721.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102721.json"},{"type":"ADVISORY","url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-wvc9-5m9h-rvxc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102721"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-threadx/netxduo","events":[{"introduced":"0"},{"last_affected":"1a0e9e43a03e37ddecfb6b49e9b078d6e1803d05"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.5.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.4.1_rel","v6.5.1.202602_rel","v6.5.0.202601_rel","v6.4.5.202504_rel","v6.4.4.202503a","v.6.4.4.202503_rel","v6.4.3_rel","v6.4.2_rel","v6.4.0_rel","v6.3.0_rel","v6.2.1_rel","v6.2.0_rel","v6.1.12_rel","v6.1.11_rel","v6.1.10_rel","v6.1.9_rel","v6.1.8_rel","v6.1.7_rel","v6.1.6_rel","v6.1.5_rel","v6.1.4_rel","v6.1.3_rel","v6.1.2_rel","v6.1_rel","v6.0.2_rel","v6.0.1_rel","v6.0_rel"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102721.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}