Junglewise Threat Intelligence

CVE-2026-9267: Eclipse tinydtls out-of-bounds read in check_server_certificate

CVE-2026-9267 · Severity: info · CVSS 6.9 · Published 2026-06-29

Vendors: Eclipse Foundation.

Executive brief

Eclipse tinydtls is a lightweight library used to provide secure communication for Internet of Things (IoT) devices. A vulnerability in how the library handles security certificates allows an unauthenticated attacker to send a specially crafted message that causes the software to crash. This results in a denial-of-service, preventing the affected IoT device from communicating securely or operating correctly.

Technical details

An out-of-bounds read vulnerability exists in the 'check_server_certificate()' function of Eclipse tinydtls. The flaw is caused by missing buffer length validation before performing uint24 reads, memcmp, and memcpy operations during the DTLS epoch 0 handshake. An unauthenticated remote attacker can exploit this by sending a crafted Certificate handshake message with a specific 'fragment_length' value. This triggers reads beyond valid buffer boundaries on both client and server paths, leading to a denial-of-service (DoS) condition, particularly on memory-constrained IoT devices. The issue was addressed in commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221.

Affected products

  • Eclipse Foundation tinydtls versions before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221

Timeline

  • 2026-06-29: advisory: NVD publication date
  • 2026-06-29: disclosed

References