High severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102712
CVE-2026-102712
Description
On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the
ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated
peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing
ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first
packet.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.