eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
References
Link | Resource |
---|---|
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059 | Third Party Advisory |
https://github.com/eProsima/Fast-DDS/issues/3236 | Third Party Advisory |
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg | Third Party Advisory |
https://www.debian.org/security/2023/dsa-5481 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-08-11 14:15
Updated : 2023-08-21 18:17
NVD link : CVE-2023-39949
Mitre link : CVE-2023-39949
CVE.ORG link : CVE-2023-39949
JSON object : View
Products Affected
debian
- debian_linux
eprosima
- fast_dds
CWE
CWE-617
Reachable Assertion