PT-2024-13956 · Eprosima+1 · Eprosima Fast Dds+1

Desglaneurs

·

Published

2024-03-06

·

Updated

2024-03-06

·

CVE-2023-50716

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eProsima Fast DDS versions prior to 2.13.0 eProsima Fast DDS versions prior to 2.12.2 eProsima Fast DDS versions prior to 2.11.3 eProsima Fast DDS versions prior to 2.10.3 eProsima Fast DDS versions prior to 2.6.7
Description The issue is related to an invalid DATA FRAG Submessage that causes a bad-free error, allowing the Fast-DDS process to be remotely terminated. When an invalid Data Frag packet is sent, the Inline qos, SerializedPayload member of object ch attempts to release memory without initialization, resulting in a 'bad-free' error.
Recommendations For versions prior to 2.13.0, update to version 2.13.0 or later. For versions prior to 2.12.2, update to version 2.12.2 or later. For versions prior to 2.11.3, update to version 2.11.3 or later. For versions prior to 2.10.3, update to version 2.10.3 or later. For versions prior to 2.6.7, update to version 2.6.7 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2023-50716
GHSA-5M2F-HVJ2-CX2H

Affected Products

Debian
Eprosima Fast Dds