CVE-2026-102762

Summary

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationNetX Duo6.0 <= 6.5.1.202602affected
Eclipse FoundationNetX Duo6.5.2.202603unaffected

Weaknesses

  • CWE-401: CWE-401 Missing Release of Memory after Effective Lifetime

References