CVE-2026-102716: High severity Eclipse Foundation NetX Duo RTSP Server vulnerability
An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests
that carry a Session header the parser cannot convert.
The Session branch returns the raw NetX error code instead of an RTSP status code:
c
/ addons/rtsp/nxrtspserver.c:2754 /
status = nxutilitystringtouint(fieldvalueptr, fieldvaluelength, &sessionid);
if (status)
{
return(status); / NXINVALIDPARAMETERS / NXSIZEERROR / NXOVERFLOW /
}
Every other branch of the same function maps its failure to an RTSP status first. The CSeq branch
eighteen lines earlier does exactly that (line 2736 returns NXRTSPSTATUSCODEBADREQUEST). The
raw code then reaches nxrtspservererrorresponsesend (nxrtspserver.c:1234), which does not
recognise it, takes a path that returns without releasing the response packet it already allocated,
and the block never goes back to the pool.
Six requests with an empty Session header against a 22 packet pool:
valid requests: after request 6: pool available = 21, AFTER = 22 / 22
malformed requests: after request 6: pool available = 16, AFTER = 17 / 22
One block per request, not returned when the client disconnects. Twenty six requests take the pool
to zero and the server starts failing allocations, after which it serves nobody. If the pool is
shared with the rest of the application, as it is in the shipped sample, the rest of the stack
stops with it.
Convert the nxutilitystringtouint failure in the Session branch into
NXRTSPSTATUSCODEBADREQUEST the way the CSeq branch does, and release the response packet on
every exit path of nxrtspservererrorresponsesend.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the RTSP Session branch, map `_nx_utility_string_to_uint` conversion failures to `NX_RTSP_STATUS_CODE_BAD_REQUEST`, matching the CSeq branch.
- Compensating control
Ensure the response packet is released on every exit path of `_nx_rtsp_server_error_response_send`, including the path handling unrecognized raw NetX error codes.
Event History
Frequently Asked Questions
What access does an attacker need to trigger the resource exhaustion?
No authentication is required. An attacker only needs to send RTSP requests to the server with a Session header whose value cannot be converted by the parser, including an empty Session header.
How can operators tell whether the server is being affected?
Monitor the RTSP server packet pool while handling malformed requests. The available packet count drops by one per triggering request and the allocated blocks are not returned when the client disconnects.