eProsima.Fast-DDS is vulnerable to Uncontrolled Resource Consumption
75
High Risk
Fast DDS deserializes DynamicData sequences from CDR payloads and resizes the backing container to the wire-provided sequence length without checking it against the declared type. A crafted sample can request an excessively large sequence. Because the deserialization path does not catch the resulting std::bad_alloc, the exception terminates the subscriber process. The fix validates sequence lengths against the type limits before allocating.
You are affected if you are using a version that falls within the vulnerable range and you use DynamicTypes to deserialize incoming samples.
eProsima.Fast-DDS is vulnerable to Uncontrolled Resource Consumption in versions 3.0.0 - 3.2.4, 3.3.0 - 3.4.2 and 3.5.0 - 3.6.1.
Upgrade the eProsima.Fast-DDS library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant