Intel

AIKIDO-2025-11006

eProsima.Fast-DDS is vulnerable to Integer Overflow

Integer OverflowCVE-2025-62599 Published Dec 30, 2025

50

Medium Risk

This Affects:

c++eProsima.Fast-DDS
0.0.1 - 2.6.10
Fixed in 2.6.11
2.7.0 - 2.14.5
Fixed in 2.14.6
3.0.0 - 3.2.3
Fixed in 3.2.4
3.3.0 - 3.3.0
Fixed in 3.3.1
3.4.0 - 3.4.0
Fixed in 3.4.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to CVE-2025-62599, CVE-2025-62600, CVE-2025-62601, CVE-2025-62602, CVE-2025-62603, and CVE-2025-64098 by fully refactoring the built-in deserializers in CDRMessage. The update introduces additional safety checks, including protections against arithmetic overflows during length validation, to ensure robust and secure deserialization. Also CVE-2025-62799 and CVE-2025-64438 were fixed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

eProsima.Fast-DDS is vulnerable to Integer Overflow in versions 0.0.1 - 2.6.10, 2.7.0 - 2.14.5, 3.0.0 - 3.2.3, 3.3.0 - 3.3.0 and 3.4.0 - 3.4.0.

How to fix this

Upgrade the eProsima.Fast-DDS library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform