Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-102715
Published:September 29, 2026
Updated:October 09, 2026
Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: The lookup that decides whether an incoming name is already stored compares the rounded slot size, so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered with the pointer to the first, and the record then carries a string up to three bytes longer than the length the caller accounted for. "_nx_mdns_packet_rr_add" (nxd_mdns.c:8911) sizes its only bound check from that stale length, and "_nx_mdns_name_string_encode" writes the real string. Two PTR records are enough, both ordinary mDNS responses to a "_http._tcp" query, with owner names whose lengths fall in the same bucket: The overflow is one to three bytes of attacker-influenced name data past "nx_packet_data_end". In a normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash. Compare the slot size against the stored string length before declaring a match, or keep the string length in the slot header and return it to the caller so the encoder and the bound check agree.
Additional Notes
The description of this vulnerability differs from MITRE.
Do you need more information?
Contact Us
CVSS v4
Base Score:
7.1
Attack Vector
ADJACENT
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.1
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH
Weakness Type (CWE)
Out-of-bounds Write
EPSS
Base Score:
0.15