{"id":"CVE-2026-102758","details":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* \u003c-- read before the bounds check */\n    if (*buffer_length \u003c 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check.","aliases":["GHSA-f95g-xc4w-mrcr"],"modified":"2026-10-02T03:31:00.498125350Z","published":"2026-09-29T17:26:44.424Z","database_specific":{"cna_assigner":"eclipse","cwe_ids":["CWE-126"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102758.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102758.json"},{"type":"ADVISORY","url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102758"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-threadx/netxduo","events":[{"introduced":"0"},{"last_affected":"1a0e9e43a03e37ddecfb6b49e9b078d6e1803d05"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.5.1.202602"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.4.1_rel","v6.5.1.202602_rel","v6.5.0.202601_rel","v6.4.5.202504_rel","v6.4.4.202503a","v.6.4.4.202503_rel","v6.4.3_rel","v6.4.2_rel","v6.4.0_rel","v6.3.0_rel","v6.2.1_rel","v6.2.0_rel","v6.1.12_rel","v6.1.11_rel","v6.1.10_rel","v6.1.9_rel","v6.1.8_rel","v6.1.7_rel","v6.1.6_rel","v6.1.5_rel","v6.1.4_rel","v6.1.3_rel","v6.1.2_rel","v6.1_rel","v6.0.2_rel","v6.0.1_rel","v6.0_rel"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102758.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}