Description
NULL Pointer Dereference on MSRP Attribute Table Exhaustion
Published: 2026-09-29
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a null pointer dereference triggered when the MSRP attribute table is exhausted, leading to a crash of the NetX Duo networking stack. The resulting instability manifests as a denial of service, disabling functionality that relies on the affected component. This flaw is categorized as CWE‑476.

Affected Systems

Eclipse Foundation’s NetX Duo embedded networking stack is affected. The advisory does not list specific version numbers, but any deployment that includes the MSRP attribute handling code remains vulnerable unless a patch or update is applied.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity. Because the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, widespread exploitation is not known. The attack vector is likely to involve an attacker sending a sequence of MSRP packets designed to exhaust the table, which is inferred from the description of table exhaustion. If successful, the attacker can cause the component to crash, resulting in a denial‑of‑service condition. No evidence of active exploitation exists at this time.

Generated by OpenCVE AI on September 29, 2026 at 23:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NetX Duo to the latest version that includes a patch for MSRP attribute table exhaustion.
  • Restrict the number of MSRP entries via configuration or apply rate limiting to prevent exhaustion.
  • Continuously monitor system logs for indications of crashes or resets caused by MSRP null pointer dereference.

Generated by OpenCVE AI on September 29, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title MSRP Attribute Table Exhaustion Causing Null Pointer Dereference in NetX Duo

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description NULL Pointer Dereference on MSRP Attribute Table Exhaustion
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:33:51.575Z

Reserved: 2026-09-29T16:15:18.490Z

Link: CVE-2026-102723

cve-icon Vulnrichment

Updated: 2026-09-29T18:33:39.512Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.830

Modified: 2026-09-29T19:17:22.380

Link: CVE-2026-102723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:30:19Z

Weaknesses