CVE-2026-102712

EUVD-2026-89175
On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the



ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated



peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing



ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first



packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown