CVE-2026-102758: Microsoft NetX Secure vulnerability
The nxsecurex509asn1tlvblockparse() function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.
The function reads the one-byte ASN.1 tag from the caller's buffer before checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns NXSECUREX509ASN1LENGTHTOOLONG, but the read has already happened one byte past the end of the buffer.
code:
nxsecure/src/nxsecurex509asn1tlvblockparse.c
UINT nxsecurex509asn1tlvblockparse(const UCHAR buffer, ULONG bufferlength, USHORT tlvtype,
USHORT tlvtagclass, ULONG tlvlength, const UCHAR tlvdata, ULONG headerlength)
{
UINT currentindex;
USHORT currenttag;
ULONG length;
ULONG lengthbytes;
currentindex = 0; currenttag = buffer[currentindex]; / <-- read before the bounds check / if (bufferlength < 1) { return(NXSECUREX509ASN1LENGTHTOOLONG); }
The remainder of the function is correctly ordered. The multi-byte length path is guarded by lengthbytes > 4 || lengthbytes > bufferlength before its read loop, the decoded value is checked against length > bufferlength, and the second single-byte length read follows its own bufferlength < 1 guard. The tag read is the only load placed ahead of its check.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
NetX Secure deployments that parse X.509 certificates from remote peers during TLS handshakes can reach the affected parsing primitive. The issue is in the ASN.1 TLV parser used underneath X.509 certificate parsing.
What does an attacker need to trigger the out-of-bounds read?
An attacker needs to supply certificate data that causes the parser to be called with a remaining buffer length of zero. The function reads the ASN.1 tag byte before checking whether at least one byte remains.
How can I determine whether my source tree contains the vulnerable code?
Inspect _nx_secure_x509_asn1_tlv_block_parse() in nx_secure_x509_asn1_tlv_block_parse.c. It is affected if it assigns current_tag from buffer[current_index] before checking whether *buffer_length is less than 1.