eProsima.Fast-DDS is vulnerable to Out-of-bounds Read
91
Critical Risk
Fast DDS receives RTPS DATA_FRAG submessages and reassembles fragmented samples. When handling the last fragment, the code derives the copy length from the wire-provided sampleSize field without confirming the datagram size. A crafted fragment with an inflated sampleSize and a short payload causes a memcpy() to read past the packet buffer into adjacent memory, whose contents can then be relayed to newly joining participants through the Discovery Server. The fix validates the incoming data length before copying so out-of-bounds bytes are never read.
You are affected if you are using a version in the vulnerable range and your participant processes RTPS DATA_FRAG submessages sourced from untrusted peers.
eProsima.Fast-DDS is vulnerable to Out-of-bounds Read in versions 0.0.1 - 2.6.11, 2.7.0 - 2.14.5, 3.0.0 - 3.2.3, 3.3.0 - 3.3.0 and 3.4.0 - 3.4.1.
Upgrade the eProsima.Fast-DDS library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant