CVE-2025-55093: Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in nxipv4packetreceive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55093?
CVE-2025-55093 is classified as a medium severity vulnerability due to the potential for memory corruption.
How do I fix CVE-2025-55093?
To remediate CVE-2025-55093, upgrade to Eclipse Foundation NetX Duo version 6.4.4 or later.
What specific issue does CVE-2025-55093 address?
CVE-2025-55093 addresses an out-of-bounds read issue in the _nx_ipv4_packet_receive() function when processing unicast DHCP messages.
Which versions of NetX Duo are affected by CVE-2025-55093?
Versions of Eclipse Foundation NetX Duo prior to 6.4.4 are affected by CVE-2025-55093.
What might be the consequence of exploiting CVE-2025-55093?
Exploiting CVE-2025-55093 could lead to memory corruption, potentially impacting application stability and security.