VYPR
High severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026

CVE-2026-102714

CVE-2026-102714

Description

_nx_icmpv6_validate_options() scans the option area with while (length > 2) (common/src/nx_icmpv6_validate_options.c:79). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns NX_SUCCESS. Its zero-length rejection never sees those bytes.

Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting nx_icmpv6_option_length << 3 with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls.

Zero length byte. The walker subtracts zero and advances zero. All four handlers loop forever — _nx_icmpv6_process_ra (nx_icmpv6_process_ra.c:245, :528), _nx_icmpv6_process_ns (:251, :329), _nx_icmpv6_process_na (:147, :156) and _nx_icmpv6_process_redirect (:247, :350). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one.

Non-zero length byte on a short residue. The three unsigned counters underflow — 2 - 8 becomes 0xFFFFFFFA — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case.

One-byte residue. The walker reads a two-byte option header, over-reading one byte.

During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (nx_icmpv6_process_ns.c:280, :293) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.