CVE-2026-102720: Medium severity Eclipse Foundation NetX Duo DHCP client vulnerability
A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a
kilobyte past the end of the received message.
The option walk keeps a pointer and an offset in step, and the only bound check uses the offset:
c
/ addons/dhcp/nxddhcpclient.c:7538, 7572 /
while (i < length - 1)
{
... size = (++data); / data moves 1: type -> length byte / data += size + 1; / data moves size + 1 more / i += size + 1; / i moves only size + 1 /
}
A TLV option occupies size + 2 bytes. data is advanced by size + 2 in total, i by size + 1, so
the offset falls one byte behind the real read position for every option the walk skips. After
enough skipped options the check i < length - 1 still holds while data is already past the end
of the message, and the subsequent read of the type and length bytes comes from whatever follows.
A single OFFER carrying a long run of skippable options is enough:
ERROR: AddressSanitizer: heap-buffer-overflow
READ of size 1 at 0x61b000000794 thread T5
#0 nxdhcpsearchbuffer addons/dhcp/nxddhcpclient.c:7541 #1 nxdhcpgetoptionvalue addons/dhcp/nxddhcpclient.c:7082
0x61b000000794 is located 164 bytes to the right of 1648-byte region
A well formed OFFER through the same path is handled normally, the client records the offer and
moves to REQUESTING, so the difference is the option layout rather than the harness.
The read runs in the DHCP client thread while the client is still unconfigured, so it happens on
every boot in reach of a hostile DHCP responder. The values read are used to configure the
interface, which is how the disclosed bytes become observable.
Advance i by size + 2, or derive the bound from data rather than keeping a second counter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Fix the DHCP option-walking logic so the offset advances by size + 2 for each TLV option, or derive the bounds directly from data instead of maintaining a second counter.
Event History
Frequently Asked Questions
Who can exploit this issue in practice?
A DHCP server can trigger it, as can anyone on the local network able to answer a client’s DHCP DISCOVER before the legitimate server. The attacker needs to send a crafted DHCP OFFER containing a long sequence of skippable options.
Does exploitation require prior access to the device?
The described attack is delivered through DHCP during address configuration. An attacker needs LAN-position capability to act as, or race, a DHCP server; no prior access to the client is described.
What happens when a malicious response is processed?
The client can read roughly a kilobyte beyond the end of the received DHCP message. The provided evidence shows an AddressSanitizer-detected heap buffer overflow read in _nx_dhcp_search_buffer.