CVE-2026-102715: Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. Th... (CVSS 7.1)

Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF; ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...) ``` The lookup that decides whether an incoming name is already stored compares the rounded slot size, so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered with the pointer to the first, and the record then carries a string up to three bytes longer than the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string....

Vulners1 min read
Read full article
CVE-2026-102715: Any host on the LAN can send two mDNS records and make the responder write past the end of its



transmit packet.



Th... (CVSS 7.1)

Read the full story at Vulners →