CVE-2026-9267: Medium severity Eclipse tinydtls vulnerability
Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the checkservercertificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a specific fragmentlength value. Attackers can exploit missing buffer length validation before uint24 reads, memcmp, and memcpy operations during DTLS epoch 0 on both client and server paths to cause denial of service on memory-constrained devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9267?
The severity of CVE-2026-9267 is medium with a CVSS score of 6.9.
What type of vulnerability is CVE-2026-9267?
CVE-2026-9267 is an out-of-bounds read vulnerability.
How do I fix CVE-2026-9267?
To fix CVE-2026-9267, update Eclipse tinydtls to a version that addresses the vulnerability.
What impact does CVE-2026-9267 have on Eclipse tinydtls?
CVE-2026-9267 allows unauthenticated attackers to read beyond valid buffer boundaries.
When was CVE-2026-9267 published?
CVE-2026-9267 was published on June 29, 2026.