{"api_version":"1","generated_at":"2026-09-29T22:26:49+00:00","cve":"CVE-2026-102758","urls":{"html":"https://cve.report/CVE-2026-102758","api":"https://cve.report/api/cve/CVE-2026-102758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102758"},"summary":{"title":"CVE-2026-102758","description":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* <-- read before the bounds check */\n    if (*buffer_length < 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.","state":"PUBLISHED","assigner":"eclipse","published_at":"2026-09-29 18:17:13","updated_at":"2026-09-29 19:00:16"},"problem_types":["CWE-126","CWE-126 CWE-126 Buffer Over-read"],"metrics":[],"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr","name":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr","refsource":"emo@eclipse.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Eclipse Foundation","product":"NetX Duo","version":"affected 6.5.1.202602 custom","platforms":[]},{"source":"CNA","vendor":"Eclipse Foundation","product":"NetX Duo","version":"unaffected 6.5.2.202603","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"tinic","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"NetX Duo","product":"NetX Duo","vendor":"Eclipse Foundation","versions":[{"lessThanOrEqual":"6.5.1.202602","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"6.5.2.202603"}]}],"credits":[{"lang":"en","type":"finder","value":"tinic"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.</p><p>The function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.</p><p>code:</p><p>nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c</p><p>```</p><p>UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,</p><code>                                          USHORT *tlv_tag_class, ULONG *tlv_length,</code><br><code>                                          const UCHAR **tlv_data, ULONG *header_length)</code><br><p>{</p><p>UINT   current_index;</p><p>USHORT current_tag;</p><p>ULONG  length;</p><p>ULONG  length_bytes;</p><code>    current_index = 0;</code><br><code>    current_tag = buffer[current_index];      /* &lt;-- read before the bounds check */</code><br><code>    if (*buffer_length &lt; 1)</code><br><code>    {</code><br><code>        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);</code><br><code>    }</code><br><p>```</p><p>The remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes &gt; 4 || length_bytes &gt; *buffer_length` before its read loop, the decoded value is checked against `length &gt; *buffer_length`, and the second single-byte length read follows its own `*buffer_length &lt; 1` guard. The tag read is the only load placed ahead of its check.</p>"}],"value":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* <-- read before the bounds check */\n    if (*buffer_length < 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-126","description":"CWE-126 Buffer Over-read","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-29T17:26:44.424Z","orgId":"e51fbebd-6053-4e49-959f-1b94eeb69a2c","shortName":"eclipse"},"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"e51fbebd-6053-4e49-959f-1b94eeb69a2c","assignerShortName":"eclipse","cveId":"CVE-2026-102758","datePublished":"2026-09-29T17:26:44.424Z","dateReserved":"2026-09-29T16:21:58.057Z","dateUpdated":"2026-09-29T17:26:44.424Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-29 18:17:13","lastModifiedDate":"2026-09-29 19:00:16","problem_types":["CWE-126","CWE-126 CWE-126 Buffer Over-read"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102758","Ordinal":"1","Title":"CVE-2026-102758","CVE":"CVE-2026-102758","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102758","Ordinal":"1","NoteData":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* <-- read before the bounds check */\n    if (*buffer_length < 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.","Type":"Description","Title":"CVE-2026-102758"}]}}}