{
  "id": 9886476,
  "title": "TDengine CVE-2026-42542: Unauthenticated Integer Underflow Crashes taosd with a Single Packet",
  "url": "https://urgent.news/2026/09/26/tdengine-cve-2026-42542-unauthenticated-integer-underflow-crashes",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-26T02:25:24.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/tdengine-cve-2026-42542-unauthenticated-integer-underflow-crashes-taosd-with-a-single-packet-38o9"
  },
  "original_language": "en",
  "account": "The vulnerability CVE-2026-42542 allows a single unauthenticated packet sent to TCP/6030 to crash the TDengine database. This is due to an integer underflow during processing, where the subtraction wraps around to a large value. This large length is then passed to memcpy, causing an out-of-bounds heap access and a crash. The crash can lead to a Denial of Service, with repeated successful attacks causing a restart loop and gaps in telemetry. Although remote code execution has not been confirmed, the impact is high as it can cause missing data, application errors, and repeated automatic restarts. TDengine version 3.4.1.6 or later is recommended to mitigate this vulnerability, as updates to this version or later contain the fix.",
  "summary": "1. Basic Information Original Title: One Packet Can Take Down the Database Behind Industrial Operations: Ridge Security Discovers CVE-2026-42542 Source: Ridge Security Published: September 23, 2026 Updated: None Severity: High Basis of Severity: A single unauthenticated packet sent to TCP/6030 can crash the database, and repeated transmission of crafted packets can sustain a restart loop and…",
  "key_points": [
    "Unauthenticated packet crashes TDengine database",
    "Integer underflow causes out-of-bounds heap access",
    "CVE-2026-42542 affects version 3.4.1.6 and earlier"
  ],
  "editors_take": "Fixing the vulnerability requires upgrading to TDengine version 3.4.1.6 or later, which prevents unauthenticated packets from crashing the database and causing denial-of-service and data gaps.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}