CRITICAL🇵🇱 Wersja polska

CVE-2023-50716

CVSS 9.6v3.1pub. 2024-03-06upd. 2025-04-16

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process can be remotely terminated. If an invalid Data_Frag packet is sent, the `Inline_qos, SerializedPayload` member of object `ch` will attempt to release memory without initialization, resulting in a 'bad-free' error. Versions 2.13.0, 2.12.2, 2.11.3, 2.10.2, and 2.6.7 fix this issue.

🤖 AI Analysis
How it works

When an attacker sends a malformed DATA_FRAG submessage, the `ch` object containing `Inline_qos` and `SerializedPayload` elements attempts to free memory that was not previously initialized. This results in a bad-free error (CWE-416: use-after-free), which causes immediate, emergency termination of the Fast DDS process. The attack can be carried out from the local network (AV:A vector) without requiring authentication and user interaction.

Impact

An attacker can remotely and immediately terminate the Fast DDS process, causing complete loss of service availability. The potential scope of the attack also includes data integrity and confidentiality (CVSS I:H, C:H), which may result from further exploitation of unstable memory state.

Mitigation & patch

eProsima Fast DDS should be updated to version 2.13.0, 2.12.2, 2.11.3, 2.10.2, or 2.6.7, which contain a patch eliminating the described vulnerability. Details are available in the vendor's security advisory on GitHub: GHSA-5m2f-hvj2-cx2h.

Who is affected

eProsima Fast DDS in versions prior to 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Eprosima Fast Dds

    APP
    Eprosima
    < 2.6.72.10.0 – 2.10.3 (excl.)2.11.0 – 2.11.3 (excl.)2.12.0 – 2.12.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-67108CRITICAL10.0PL ✓same product

eProsima Fast-DDS: błędna walidacja odwołania certyfikatów/tokenów

CVE-2024-28231CRITICAL9.6PL ✓same product

Heap buffer overflow w eprosima Fast DDS via manipulowany DATA Submessage

CVE-2023-50257CRITICAL9.6PL ✓same product

eProsima Fast DDS — podatność rozłączenia subskrybentów RTPS w SROS2

CVE-2025-62600HIGH8.6same product

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object M...

CVE-2025-62599HIGH8.6same product

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object M...