Kestrel
대시보드로 돌아가기
CVE-2026-102715UNKNOWNMITRENVD대응게시일: 2026. 09. 29.수정일: 2026. 09. 29.CNA: emo@eclipse.orgAwaiting Analysis

Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table store

Memory-Corruption

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
—unknown

이론적 심각도 점수

EPSS
—

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

버전별 점수
CVSS 4.07.1HIGH· 악용성숙도 NOT_DEFINED

CVSS 벡터 정보 없음

약점 (CWE)

  • CWE-787

    경계 밖 쓰기 — 버퍼 범위를 벗어난 메모리에 써서 충돌·코드 실행으로 이어질 수 있음.

상세 설명

Any host on the LAN can send two mDNS records and make the responder write past the end of its

transmit packet.

The string table stores each name in a slot rounded up to a multiple of four:

text
1
2
3
4/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */
5
6
7
8memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;
9
10
11
12...
13
14
15
16len = *((USHORT*)(p - 2)); /* slot size, not string length */
17
18
19
20if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)
21
22

The lookup that decides whether an incoming name is already stored compares the rounded slot size,

so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered

with the pointer to the first, and the record then carries a string up to three bytes longer than

the length the caller accounted for. _nx_mdns_packet_rr_add (nxd_mdns.c:8911) sizes its only

bound check from that stale length, and _nx_mdns_name_string_encode writes the real string.

Two PTR records are enough, both ordinary mDNS responses to a _http._tcp query, with owner names

whose lengths fall in the same bucket:

bash
1
2
3
4==87491==ERROR: AddressSanitizer: heap-buffer-overflow
5
6
7
8WRITE of size 1 at 0x611000000124 thread T5
9
10 #0 _nx_mdns_name_string_encode addons/mdns/nxd_mdns.c:13096
11 #1 _nx_mdns_packet_rr_add addons/mdns/nxd_mdns.c:8911
12
13
140x611000000124 is 0 bytes to the right of 228-byte region
15
16

The overflow is one to three bytes of attacker-influenced name data past nx_packet_data_end. In a

normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible

effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.

Compare the slot size against the stored string length before declaring a match, or keep the

string length in the slot header and return it to the caller so the encoder and the bound check

agree.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.