Any host on the LAN can send two mDNS records and make the responder write past the end of its



transmit packet.



The string table stores each name in a slot rounded up to a multiple of four:



```c



/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */



memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;



...



len = *((USHORT*)(p - 2)); /* slot size, not string length */



if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)



```



The lookup that decides whether an incoming name is already stored compares the rounded slot size,



so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered



with the pointer to the first, and the record then carries a string up to three bytes longer than



the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only



bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.



Two PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names



whose lengths fall in the same bucket:



```



==87491==ERROR: AddressSanitizer: heap-buffer-overflow



WRITE of size 1 at 0x611000000124 thread T5

#0 _nx_mdns_name_string_encode addons/mdns/nxd_mdns.c:13096
#1 _nx_mdns_packet_rr_add addons/mdns/nxd_mdns.c:8911


0x611000000124 is 0 bytes to the right of 228-byte region



```



The overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a



normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible



effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.



Compare the slot size against the stored string length before declaring a match, or keep the



string length in the slot header and return it to the caller so the encoder and the bound check



agree.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF; ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...) ``` The lookup that decides whether an incoming name is already stored compares the rounded slot size, so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered with the pointer to the first, and the record then carries a string up to three bytes longer than the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string. Two PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names whose lengths fall in the same bucket: ``` ==87491==ERROR: AddressSanitizer: heap-buffer-overflow WRITE of size 1 at 0x611000000124 thread T5 #0 _nx_mdns_name_string_encode addons/mdns/nxd_mdns.c:13096 #1 _nx_mdns_packet_rr_add addons/mdns/nxd_mdns.c:8911 0x611000000124 is 0 bytes to the right of 228-byte region ``` The overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash. Compare the slot size against the stored string length before declaring a match, or keep the string length in the slot header and return it to the caller so the encoder and the bound check agree.
Title mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:42:21.812Z

Reserved: 2026-09-29T16:15:11.235Z

Link: CVE-2026-102715

cve-icon Vulnrichment

Updated: 2026-09-29T18:41:59.861Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:10.780

Modified: 2026-09-29T19:17:20.627

Link: CVE-2026-102715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses