CVE-2025-55092: Potential out of bound read in _nx_ipv4_option_process()
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in nxipv4optionprocess() when processing an IPv4 packet with the timestamp option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55092?
CVE-2025-55092 is classified as a medium severity vulnerability due to the potential out of bounds read issue.
How do I fix CVE-2025-55092?
To fix CVE-2025-55092, upgrade Eclipse Foundation NetX Duo to version 6.4.4 or later.
What causes the issue in CVE-2025-55092?
CVE-2025-55092 is caused by improper handling of the timestamp option in the _nx_ipv4_option_process() function when processing IPv4 packets.
Who is affected by CVE-2025-55092?
CVE-2025-55092 affects users of Eclipse Foundation NetX Duo versions prior to 6.4.4.
What should I do if I cannot upgrade to fix CVE-2025-55092?
If upgrading is not possible for CVE-2025-55092, implement network access controls to mitigate potential exploitation.