eProsima.Fast-DDS is vulnerable to Uncontrolled Recursion
75
High Risk
Fast DDS parses DDS-SQL filter expressions carried in PID_CONTENT_FILTER_PROPERTY discovery (SEDP) parameters using a recursive-descent grammar. The parser applies no recursion-depth or expression-complexity limit, so a filter expression with many nested parentheses drives unbounded recursive descent. A single crafted discovery message can therefore exhaust the process stack and terminate any participant that evaluates the expression. The fix caps the number of subexpressions and the overall expression length before parsing.
You are affected if you are using a version that falls within the vulnerable range and you use a ContentFilteredTopic evaluated with the built-in DDS-SQL filter.
eProsima.Fast-DDS is vulnerable to Uncontrolled Recursion in versions 2.5.1 - 2.6.11, 2.7.0 - 3.2.4, 3.3.0 - 3.4.2 and 3.5.0 - 3.5.0.
Upgrade the eProsima.Fast-DDS library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant