CVE-2021-38423: GurumDDS Heap-based Incorrect Calculation of Buffer Size
Published May 5, 2022
·Updated
All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow.
Affected Software
8 affected componentsFixes available
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Eclipse CycloneDDS<0.8.0
0.8.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing eProsima Fast DDS (#2269)<2.4.0
2.4.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing GurumNetworks GurumDDS
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Object Computing, Inc. (OCI) OpenDDS<3.18.1
3.18.1
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing RTI Connext DDS Micro>=3.0.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing TwinOaks Computing CoreDX DDS<5.9.1
5.9.1
Gurum GurumDDS
Remediation
Information
Users should contact GurumNetworks for assistance. contact@gurum.cc
Event History
May 5, 2022
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-38423?
CVE-2021-38423 has been rated as a critical vulnerability due to its potential to cause a buffer overflow.
2
Which versions of GurumDDS are affected by CVE-2021-38423?
CVE-2021-38423 affects all versions of GurumDDS and associated products including Eclipse CycloneDDS, eProsima Fast DDS, and OpenDDS.
3
How do I fix CVE-2021-38423?
To fix CVE-2021-38423, update GurumDDS and related products to the latest patched versions indicated by the vendor.
4
What risks are associated with CVE-2021-38423?
The risks associated with CVE-2021-38423 include potential arbitrary code execution and denial of service through buffer overflow.
5
Is there a workaround for CVE-2021-38423?
There are currently no known workarounds for CVE-2021-38423, so upgrading to a secure version is recommended.