PT-2026-50864 · Eclipse Foundation · Eclipse Threadx Netx Duo

Decsecre583

·

Publicado

2026-06-19

·

Atualizado

2026-06-19

·

CVE-2026-11576

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx file close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup label before any file open operation has occurred, causing fx file close() to operate on an uninitialized file handle, leading to undefined behavior, double-close issues, or memory corruption.

Correção

Use of Uninitialized Resource

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-11576

Produtos afetados

Eclipse Threadx Netx Duo