TDengine Flaw CVE-2026-42542 Lets Single Packet Crash Industrial Database Service
Ridge Security disclosed CVE-2026-42542 on September 23, 2026, a high-severity vulnerability in TDengine's unauthenticated RPC processing on TCP port 6030. An integer underflow in the message-length calculation causes a signed-to-unsigned wrap-around, passing an oversized value to memcpy and triggering an out-of-bounds heap access that crashes the taosd process. An attacker with network access to the port — including from a compromised internal host on a flat OT network — can repeatedly send crafted packets to sustain a restart loop and create gaps in data ingestion. The confirmed impact is Denial of Service; remote code execution has not been verified. TDengine users are advised to upgrade to version 3.4.1.6 or later and restrict network access to TCP/6030.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in