Description
A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the



received datagram.



Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229,



1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose



only limits are the destination buffer and a NUL byte:



```c



/* addons/tftp/nxd_tftp_client.c:1769 */



for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++)



```



Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no



terminating NUL, which a server controls completely, walks the loop off the end of the packet until



it happens to meet a zero byte or fills the 64 byte destination.



```



ERROR: AddressSanitizer: heap-buffer-overflow



READ of size 1 at 0x60d0000000c8 thread T4

#0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769


0x60d0000000c8 is 0 bytes to the right of 136-byte region



```



The open path has the same loop at :1327 and reports the same way. What is read lands in



`nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent



packet pool memory ends up in whatever the device does with the error text.



Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title TFTP Client Buffer Overflow via Malformed ERROR Packet

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:36:05.599Z

Reserved: 2026-09-29T16:15:17.020Z

Link: CVE-2026-102721

cve-icon Vulnrichment

Updated: 2026-09-29T18:35:40.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.540

Modified: 2026-09-29T19:17:21.417

Link: CVE-2026-102721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses