CVE-2026-102715: mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet
Any host on the LAN can send two mDNS records and make the responder write past the end of its
transmit packet.
The string table stores each name in a slot rounded up to a multiple of four:
c
/ addons/mdns/nxdmdns.c:11436, 11443, 11447 /
memorylen = ((memorylen & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;
...
len = ((USHORT)(p - 2)); / slot size, not string length /
if ((len == memorylen) && ... nxmdnsnamematch(start, memoryptr, memorysize) ...)
The lookup that decides whether an incoming name is already stored compares the rounded slot size,
so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered
with the pointer to the first, and the record then carries a string up to three bytes longer than
the length the caller accounted for. nxmdnspacketrradd (nxdmdns.c:8911) sizes its only
bound check from that stale length, and nxmdnsnamestringencode writes the real string.
Two PTR records are enough, both ordinary mDNS responses to a http.tcp query, with owner names
whose lengths fall in the same bucket:
==87491==ERROR: AddressSanitizer: heap-buffer-overflow
WRITE of size 1 at 0x611000000124 thread T5
#0 nxmdnsnamestringencode addons/mdns/nxdmdns.c:13096 #1 nxmdnspacketrradd addons/mdns/nxdmdns.c:8911
0x611000000124 is 0 bytes to the right of 228-byte region
The overflow is one to three bytes of attacker-influenced name data past nxpacketdataend. In a
normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible
effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.
Compare the slot size against the stored string length before declaring a match, or keep the
string length in the slot header and return it to the caller so the encoder and the bound check
agree.
Affected Software
Event History
Frequently Asked Questions
What network position does an attacker need?
The attacker needs to be able to send mDNS traffic from the same LAN as the affected responder. The described trigger uses ordinary mDNS responses.
What crafted traffic is required to trigger the overflow?
The trigger uses two PTR records in response to a _http._tcp query. Their owner names must fall into the same four-byte-rounded string-cache size bucket, with the later name longer than the name already cached.