Intel

AIKIDO-2025-11006

eProsima.Fast-DDS is vulnerable to Integer Overflow

Integer OverflowCVE-2025-62599 Published Dec 30, 2025

50

Medium Risk

This Affects:

c++eProsima.Fast-DDS
0.0.1 - 2.6.10
Fixed in 2.6.11
2.7.0 - 2.14.5
Fixed in 2.14.6
3.0.0 - 3.2.3
Fixed in 3.2.4
3.3.0 - 3.3.0
Fixed in 3.3.1
3.4.0 - 3.4.0
Fixed in 3.4.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to CVE-2025-62599, CVE-2025-62600, CVE-2025-62601, CVE-2025-62602, CVE-2025-62603, and CVE-2025-64098 by fully refactoring the built-in deserializers in CDRMessage. The update introduces additional safety checks, including protections against arithmetic overflows during length validation, to ensure robust and secure deserialization. Also CVE-2025-62799 and CVE-2025-64438 were fixed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

eProsima.Fast-DDS is vulnerable to Integer Overflow in versions 0.0.1 - 2.6.10, 2.7.0 - 2.14.5, 3.0.0 - 3.2.3, 3.3.0 - 3.3.0 and 3.4.0 - 3.4.0.

How to fix this

Upgrade the eProsima.Fast-DDS library to the patch version.