CVE-2025-55090: Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo
Published Oct 16, 2025
·Updated
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in nxipv4packetreceive() function when received an Ethernet frame with less than 4 bytes of IP packet.
Affected Software
2 affected components
Eclipse Foundation NetX Duo<6.4.4
Eclipse ThreadX NetX Duo<6.4.4.202503
Event History
Oct 16, 2025
CVE Published
via MITRE·06:43 AM
Data Sourced
via MITRE·06:43 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55090?
CVE-2025-55090 is classified as a medium severity vulnerability due to the potential for an out of bounds read.
2
How do I fix CVE-2025-55090?
To fix CVE-2025-55090, update NetX Duo to version 6.4.4 or later.
3
What versions of NetX Duo are affected by CVE-2025-55090?
CVE-2025-55090 affects all versions of NetX Duo prior to 6.4.4.
4
What type of vulnerability is CVE-2025-55090?
CVE-2025-55090 is an out of bounds read vulnerability found in the _nx_ipv4_packet_receive() function.
5
What could be the impact of exploiting CVE-2025-55090?
Exploiting CVE-2025-55090 could lead to potential unauthorized data access or application crashes.