CVE-2026-102716: High severity Eclipse Foundation NetX Duo RTSP Server vulnerability

Published Sep 29, 2026
·
Updated

An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests

that carry a Session header the parser cannot convert.

The Session branch returns the raw NetX error code instead of an RTSP status code:

c

/ addons/rtsp/nxrtspserver.c:2754 /

status = nxutilitystringtouint(fieldvalueptr, fieldvaluelength, &sessionid);

if (status)

{

return(status); / NXINVALIDPARAMETERS / NXSIZEERROR / NXOVERFLOW /

}

Every other branch of the same function maps its failure to an RTSP status first. The CSeq branch

eighteen lines earlier does exactly that (line 2736 returns NXRTSPSTATUSCODEBADREQUEST). The

raw code then reaches nxrtspservererrorresponsesend (nxrtspserver.c:1234), which does not

recognise it, takes a path that returns without releasing the response packet it already allocated,

and the block never goes back to the pool.

Six requests with an empty Session header against a 22 packet pool:

valid requests: after request 6: pool available = 21, AFTER = 22 / 22

malformed requests: after request 6: pool available = 16, AFTER = 17 / 22

One block per request, not returned when the client disconnects. Twenty six requests take the pool

to zero and the server starts failing allocations, after which it serves nobody. If the pool is

shared with the rest of the application, as it is in the shipped sample, the rest of the stack

stops with it.

Convert the nxutilitystringtouint failure in the Session branch into

NXRTSPSTATUSCODEBADREQUEST the way the CSeq branch does, and release the response packet on

every exit path of nxrtspservererrorresponsesend.

Affected Software

1 affected component
Eclipse Foundation NetX Duo RTSP Server

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the RTSP Session branch, map `_nx_utility_string_to_uint` conversion failures to `NX_RTSP_STATUS_CODE_BAD_REQUEST`, matching the CSeq branch.

  2. Compensating control

    Ensure the response packet is released on every exit path of `_nx_rtsp_server_error_response_send`, including the path handling unrecognized raw NetX error codes.

Event History

Sep 29, 2026
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to trigger the resource exhaustion?

No authentication is required. An attacker only needs to send RTSP requests to the server with a Session header whose value cannot be converted by the parser, including an empty Session header.

2

How can operators tell whether the server is being affected?

Monitor the RTSP server packet pool while handling malformed requests. The available packet count drops by one per triggering request and the allocated blocks are not returned when the client disconnects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203