CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosd
CVE-2026-42542 (TL-2026-2746), also tracked as GHSA-vg95-j2hf-hvjx, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-09-28. It has no confirmed attribution, affects TDengine (TAOS Data) TDengine TSDB (taosd RPC service, TCP/6030), references 1 CVE (CVE-2026-42542), maps to 4 MITRE ATT&CK techniques (T0814, T0819, T1190), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2746
- Threat ID
- TL-2026-2746
- Also known as
- GHSA-vg95-j2hf-hvjx, TD-SEC-2026-001
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- industrial, energy-utilities, automotive, iot, telecoms, building-automation, ev-charging, manufacturing
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
An integer underflow (CWE-191) in uvConnMayGetUserInfo() in TDengine 3.4.0.0 through 3.4.1.5 lets an unauthenticated remote attacker crash the taosd server with one crafted RPC packet over TCP/6030, causing denial of service. Fixed in 3.4.1.6. Ridge Security reports no in-the-wild exploitation telemetry and no known public exploit code; CVE-2026-42542 is not in CISA KEV as of the 2026.09.27 catalog.
How CVE-2026-42542 works
CVE-2026-42542 is a pre-authentication integer underflow in the RPC transport layer of TDengine, an open-source distributed time-series database used for industrial telemetry, IoT, energy and utilities, connected-vehicle, EV-charging, telecom and building-automation data. The flaw is in uvConnMayGetUserInfo() at source/libs/transport/src/transSvr.c (line 860 per the vendor advisory) and affects TDengine 3.4.0.0 through 3.4.1.5. It was discovered by the Ridge Security Threat Research Team (Yan Zhou; the GitHub advisory credits discoverer Yan @ Ridge Security and reporter shook-zhou) while testing open-source applications used in IoT/OT environments.
Root cause: the function subtracts sizeof(STransMsgHead) plus a user-info offset from msgLen, a signed 32-bit integer (int32_t len) read directly from the attacker-controlled message header. Because sizeof(STransMsgHead) is an unsigned size_t, the signed value is promoted, and when msgLen is smaller than the header plus offset the subtraction wraps to a value near 2^64 on 64-bit systems (about 18 exabytes per the advisory). That value is passed to memcpy() as the copy length, producing an out-of-bounds heap access and a segmentation fault that terminates the taosd process. Ridge Security describes the fixed header as 64 or 192 bytes depending on message type; the advisory gives the required user-info offset as 24-128 bytes.
The vendor advisory documents the reproduction conditions: a malformed STransMsgHead with withUserInfo=1, version=3, and msgLen set to sizeof(STransMsgHead)+10 (too short for the required offset), carrying a valid CRC32 checksum. The CRC32 is a public, unkeyed integrity algorithm the sender computes, so it is not a barrier; no credentials, session state or user interaction are required, and the taosd RPC service listens on TCP/6030 by default. The vendor advisory and Ridge Security both state the confirmed impact is availability loss only; the advisory notes pre-crash heap memory corruption and that more sophisticated exploitation is conceivable, but no code-execution primitive has been demonstrated.
Exploitation status: Ridge Security states it has no telemetry indicating in-the-wild exploitation and is aware of no public exploit code. It holds a working proof of concept that reproduces the crash, withholds it from public release, and shares it with vetted defenders/vendors/CERTs under non-redistribution terms. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (version 2026.09.27, 1,728 entries), and third-party trackers put its EPSS score below 1% (OpenCVE 0.00633; Strix/CyberStrike 0.54%). Independent coverage describes the fix as a three-line guard around the subtraction. Repeated transmission of the packet can sustain an outage when a supervisor such as systemd restarts taosd (a 'permanent crash cycle'); consequences include lost uncommitted writes, halted data collection, and lost visibility or alerting in OT environments. Ridge Security's researcher warned that outages could serve as cover for secondary attacks. Highest risk is on flat networks where TCP/6030 is broadly reachable and in embedded/OEM appliances where operators may not know TDengine is present; industrial environments also face patch delays from maintenance windows and vendor support requirements.
Remediation: upgrade to TDengine 3.4.1.6 or later, which rejects the packet when withUserInfo is set and msgLen is shorter than sizeof(STransMsgHead)+offset, logging 'withUserInfo set but msgLen %d too short (need %d)' before any arithmetic is done (fix commit 003e8a5f102f6ee24ada79e087bdbbea1442ca88; introducing commit 6e95fe58a4e69509bd36aacbbc052ab264526942 per OSV). Until patched, restrict TCP/6030 with host firewalls or network ACLs to authorized application hosts, inventory all instances including bundled ones, and monitor for taosd segmentation faults, crash loops and ingestion gaps. Ridge Security also noted, separately from this CVE, that TDengine defaults to MD5 password hashing and SHA-1 RPC connection signatures. The same Ridge Security post discloses an unrelated low-severity NanoMQ issue (CVE-2026-44639, CVSS 3.7, O(N^2) MQTT v5 property decoding, fixed in 0.24.14).
MITRE ATT&CK techniques used in TL-2026-2746
Inhibit Response Function
Initial Access
T0819 Exploit Public-Facing Application; T1190 Exploit Public-Facing Application
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Affected products and versions in CVE-2026-42542
- TDengine (TAOS Data) — TDengine TSDB (taosd RPC service, TCP/6030)
Vulnerable versions: 3.4.0.0 through 3.4.1.5
Fixed in: 3.4.1.6
Remediation for CVE-2026-42542
Patches
- TDengine 3.4.1.6 (validates msgLen against sizeof(STransMsgHead) + offset at the top of uvConnMayGetUserInfo()); fix commit 003e8a5f102f6ee24ada79e087bdbbea1442ca88
Immediate actions
- Upgrade TDengine (taosd) to 3.4.1.6 or later
- Restrict TCP/6030 with host firewall rules or network ACLs to authorized application hosts only
- Inventory every TDengine instance, including bundled/OEM/embedded deployments
Workarounds
- No vendor workaround beyond network-level restriction of TCP/6030 to trusted clients
Longer-term hardening
- Segment OT/IoT telemetry databases away from flat or broadly reachable networks; TCP/6030 should not be internet-exposed
- Alert on taosd segmentation faults, core dumps, and supervisor/systemd restart loops
- Alert on gaps in time-series data ingestion and on short-lived TCP/6030 connections from unexpected sources
- Inspect RPC traffic for packets whose declared msgLen is smaller than the fixed header size (never legitimate)
- Plan patch windows for OEM-bundled TDengine with the appliance vendor
CVEs associated with CVE-2026-42542
Weaknesses (CWE) in CVE-2026-42542
CWE-191
Timeline of CVE-2026-42542
- TDengine publishes GitHub advisory GHSA-vg95-j2hf-hvjx (TD-SEC-2026-001) for CVE-2026-42542, rated High (CVSS 7.5), affecting 3.4.0.0-3.4.1.5 with the fix in 3.4.1.6; discoverer Yan of Ridge Security, reporter shook-zhou. The advisory documents the malformed-header reproduction conditions and the patch logic.
- CVE-2026-42542 is published in NVD (CWE-191, CVSS 7.5 from the GitHub CNA) and OSV, referencing the ver-3.4.1.6 release and the vendor advisory.
- NVD record last modified and marked Analyzed, with CPE cpe:2.3:a:tdengine:tdengine covering 3.4.0.0 through 3.4.1.5 (per OpenCVE/Strix); EPSS remains below 1%.
- OSV record modified; it lists introduced commit 6e95fe58a4e69509bd36aacbbc052ab264526942 (3.4.0.0) and fixed commit 003e8a5f102f6ee24ada79e087bdbbea1442ca88 (3.4.1.6).
- Ridge Security publishes its technical write-up: signed msgLen minus unsigned header size wraps to ~2^64 and reaches memcpy(); no in-the-wild telemetry, no public exploit; a working PoC is held privately and shared only with vetted defenders. Also discloses NanoMQ CVE-2026-44639.
- Trade press (Dark Reading, Security Boulevard, The IT Nerd) covers the flaw, stressing OT/IoT exposure, that TDengine may be embedded in appliances where operators are unaware of it, and that patching in industrial environments is slowed by maintenance windows.
- CISA KEV catalog version 2026.09.27 (1,728 entries) contains no CVE-2026-42542 or TDengine entry, consistent with the vendor's no-exploitation statement.
Sources cited for CVE-2026-42542
- Integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS) - GHSA-vg95-j2hf-hvjx
- One Packet Can Take Down the Database Behind Industrial Operations: Ridge Security Discovers CVE-2026-42542
- NVD - CVE-2026-42542
- OSV - CVE-2026-42542 (GHSA-vg95-j2hf-hvjx)
- TDengine TSDB Docs - Security Advisories (TD-SEC-2026-001)
- TDengine release ver-3.4.1.6
- OpenCVE - CVE-2026-42542 (EPSS, CPE, KEV status)
- One Packet Can Crash OT Servers in Industrial Sectors (Dark Reading)
- Security Boulevard: One Packet Can Take Down the Database Behind Industrial Operations
- TDengine CVE-2026-42542: Unauthenticated Integer Underflow Crashes taosd with a Single Packet (DEV Community)
- New OT zero-day can take down a database with one packet, and you may not know it's there (The IT Nerd)
- CISA Known Exploited Vulnerabilities catalog (checked: no CVE-2026-42542 entry, version 2026.09.27)
More in vulnerability
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
Detection coverage for TL-2026-2746
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2746 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.