CVE-2023-39534: Malformed GAP submessage triggers assertion failure
Published Aug 11, 2023
·Updated
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a patch for this issue.
Affected Software
9 affected componentsFixes available
ubuntu/fastdds<2.10.1+
2.10.1+
ubuntu/fastdds<2.5.0+
2.5.0+
ubuntu/fastdds<2.9.1+
2.9.1+
debian/fastdds
2.1.0+ds-9+deb11u12.9.1+ds-1+deb12u22.11.2+ds-6
eProsima Fast DDS>=2.6.0<2.6.5
eProsima Fast DDS>=2.9.0<2.9.2
eProsima Fast DDS=2.10.0-rc1
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Event History
Aug 11, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionSeverityWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:24 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39534?
CVE-2023-39534 is a vulnerability in eprosima Fast DDS that can trigger an assertion failure and crash the system.
2
Which versions of eprosima Fast DDS are affected by CVE-2023-39534?
Versions prior to 2.10.0, 2.9.2, and 2.6.5 of eprosima Fast DDS are affected by CVE-2023-39534.
3
How can CVE-2023-39534 be exploited?
CVE-2023-39534 can be exploited by sending a malformed GAP submessage to the FastDDS system.
4
How severe is CVE-2023-39534?
CVE-2023-39534 has a severity rating of 7.5 (high).
5
How can I fix CVE-2023-39534?
You can fix CVE-2023-39534 by updating to version 2.10.0, 2.9.2, or 2.6.5 of eprosima Fast DDS.