TDengine CVE-2026-42542 (CVSS 7.5): unauth RPC integer underflow → taosd crash (port 6030); fix 3.4.1.6 — Ridge / vendor
Ridge Security (public write-up 23 September 2026; SecurityWeek In Other News 25 Sep) and TDengine security advisories document CVE-2026-42542 (TD-SEC-2026-001; GHSA-vg95-j2hf-hvjx; vendor published 4 June 2026; reporter Yan @ Ridge Security): an integer underflow in uvConnMayGetUserInfo() (transSvr.c) on the pre-authentication RPC path lets an unauthenticated remote attacker crash taosd with one crafted packet to the default TCP 6030 listener (CWE-191). Confirmed impact is denial of service (heap overflow / SIGSEGV); Ridge does not claim RCE and reports no in-the-wild exploitation telemetry. CVSS 7.5 HIGH. Affected: TDengine >= 3.4.0.0 through 3.4.1.5; fixed in 3.4.1.6. Relevant to industrial telemetry, energy/utilities, IoT and OT monitoring stacks that embed TDengine. Primary: Ridge Security blog + TDengine security advisories / GHSA.
- Product
- TDengine (taosd) time-series database — RPC on TCP 6030
- Versions
- Affected: >= 3.4.0.0, <= 3.4.1.5. Fixed: 3.4.1.6 and later.
- CVSS
- 7.5
- Exploited in Australia?
- unknown
- Patch to
- Upgrade TDengine to 3.4.1.6 or later; restrict TCP 6030 to authorised application hosts only (not internet-facing); inventory OEM/bundled TDengine in OT/IoT stacks; monitor taosd crash/restart loops correlated with untrusted RPC sources.
Primary: Ridge Security — TDengine CVE-2026-42542 one-packet DoS (23 Sep 2026) · Vendor: TDengine — Security Advisories (CVE-2026-42542 / TD-SEC-2026-001) · CVE: CVE-2026-42542 · GitHub GHSA-vg95-j2hf-hvjx — TDengine RPC integer underflow DoS
