eProsima.Fast-DDS is vulnerable to Denial of Service (DoS)
86
High Risk
eProsima.Fast-DDS processes RTPS HEARTBEAT submessages on RELIABLE readers without bounding the first sequence number. A crafted HEARTBEAT with a huge firstSN stores that value as the writer low mark, then StatefulReader::NotifyChanges() loops from the last notified sequence up to that mark and runs a linear history lookup on every iteration. That unbounded loop can hang the subscriber until the process is killed. The fix marks all pending sequences as notified in constant time instead of iterating each missing number.
You are affected if you are using a version that falls within the vulnerable range and your participant uses RELIABLE QoS readers reachable on the DDS domain.
eProsima.Fast-DDS is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.6.10, 2.7.0 - 2.14.5, 3.0.0 - 3.2.3, 3.3.0 - 3.3.0 and 3.4.0 - 3.4.1.
Upgrade the eProsima.Fast-DDS library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant