
Worth a read if you run time-series databases in OT or IoT environments: https://ridgesecurity.ai/blog/one-packet-can-take-down-the-database-behind-industrial-operations-ridge-security-discovers-cve-2026-42542/ Ridge Security's research team disclosed CVE-2026-42542 (CVSS 7.5), a pre-authentication flaw in TDengine's RPC handler. A signed length value from the network is subtracted from an unsigned header size before any bounds check. That lets an undersized value wrap to a huge number that gets passed to memcpy(), so a single malformed packet to port 6030 crashes taosd. Versions 3.4.0.0 through 3.4.1.5 are affected, and the fix is in 3.4.1.6. #VulnerabilityResearch #OTSecurity #IoTSecurity #CVE
