PT-2025-11036 · Eclipse Foundation+3 · Eclipse Cyclonedds+2

Robert Femmer

+1

·

Published

2025-03-12

·

Updated

2025-03-14

·

CVE-2024-10838

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: The product name cannot be determined.
Description: An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory, potentially leading to the inclusion of secret data or pointers that reveal the layout of the address space into a deserialized data structure. This could result in thread crashes or denial of service conditions. Unauthenticated users could exploit this issue to access sensitive data or crash threads.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10838
GHSA-6JJ6-W25P-JC42

Affected Products

Eclipse Cyclonedds
Cyclone Data Distribution Service
Cyclonedds