PT-2026-50864 · Eclipse Foundation · Eclipse Threadx Netx Duo
Decsecre583
·
Publicado
2026-06-19
·
Atualizado
2026-06-19
·
CVE-2026-11576
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx file close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup label before any file open operation has occurred, causing fx file close() to operate on an uninitialized file handle, leading to undefined behavior, double-close issues, or memory corruption.
Correção
Use of Uninitialized Resource
Double Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Eclipse Threadx Netx Duo