CVE-2026-102715: mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet

Published Sep 29, 2026
·
Updated

Any host on the LAN can send two mDNS records and make the responder write past the end of its

transmit packet.

The string table stores each name in a slot rounded up to a multiple of four:

c

/ addons/mdns/nxdmdns.c:11436, 11443, 11447 /

memorylen = ((memorylen & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;

...

len = ((USHORT)(p - 2)); / slot size, not string length /

if ((len == memorylen) && ... nxmdnsnamematch(start, memoryptr, memorysize) ...)

The lookup that decides whether an incoming name is already stored compares the rounded slot size,

so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered

with the pointer to the first, and the record then carries a string up to three bytes longer than

the length the caller accounted for. nxmdnspacketrradd (nxdmdns.c:8911) sizes its only

bound check from that stale length, and nxmdnsnamestringencode writes the real string.

Two PTR records are enough, both ordinary mDNS responses to a http.tcp query, with owner names

whose lengths fall in the same bucket:

==87491==ERROR: AddressSanitizer: heap-buffer-overflow

WRITE of size 1 at 0x611000000124 thread T5

#0 nxmdnsnamestringencode addons/mdns/nxdmdns.c:13096 #1 nxmdnspacketrradd addons/mdns/nxdmdns.c:8911

0x611000000124 is 0 bytes to the right of 228-byte region

The overflow is one to three bytes of attacker-influenced name data past nxpacketdataend. In a

normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible

effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.

Compare the slot size against the stored string length before declaring a match, or keep the

string length in the slot header and return it to the caller so the encoder and the bound check

agree.

Affected Software

1 affected component
Microsoft NetX Duo

Event History

Sep 29, 2026
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What network position does an attacker need?

The attacker needs to be able to send mDNS traffic from the same LAN as the affected responder. The described trigger uses ordinary mDNS responses.

2

What crafted traffic is required to trigger the overflow?

The trigger uses two PTR records in response to a _http._tcp query. Their owner names must fall into the same four-byte-rounded string-cache size bucket, with the later name longer than the name already cached.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203