First published: Fri Aug 11 2023(Updated: )
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a patch for this issue.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/fastdds | <2.10.1+ | 2.10.1+ |
ubuntu/fastdds | <2.5.0+ | 2.5.0+ |
ubuntu/fastdds | <2.9.1+ | 2.9.1+ |
eprosima Fast DDS | >=2.6.0<2.6.5 | |
eprosima Fast DDS | >=2.9.0<2.9.2 | |
eprosima Fast DDS | =2.10.0-rc1 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
>=2.6.0<2.6.5 | ||
>=2.9.0<2.9.2 | ||
=2.10.0-rc1 | ||
=11.0 | ||
=12.0 | ||
debian/fastdds | 2.1.0+ds-9+deb11u1 2.9.1+ds-1+deb12u2 2.11.2+ds-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39534 is a vulnerability in eprosima Fast DDS that can trigger an assertion failure and crash the system.
Versions prior to 2.10.0, 2.9.2, and 2.6.5 of eprosima Fast DDS are affected by CVE-2023-39534.
CVE-2023-39534 can be exploited by sending a malformed GAP submessage to the FastDDS system.
CVE-2023-39534 has a severity rating of 7.5 (high).
You can fix CVE-2023-39534 by updating to version 2.10.0, 2.9.2, or 2.6.5 of eprosima Fast DDS.