CVE-2023-39945: Malformed serialized data in a data submessage leads to unhandled exception
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled BadParamException in fastcdr, which in turn crashes fastdds. Versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5 contain a patch for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39945?
CVE-2023-39945 is a vulnerability in eprosima Fast DDS that allows a data submessage sent to the PDP port to raise an unhandled BadParamException, leading to a crash.
What is the severity of CVE-2023-39945?
CVE-2023-39945 has a severity value of 7.5, which is considered high.
Which versions of eprosima Fast DDS are affected by CVE-2023-39945?
Versions 2.6.0 to 2.6.5, 2.9.0 to 2.9.2, and 2.10.0 to 2.10.2 of eprosima Fast DDS are affected by CVE-2023-39945.
How can I fix CVE-2023-39945?
To fix CVE-2023-39945, make sure to update to version 2.11.0 or later of eprosima Fast DDS.
Is Debian Linux affected by CVE-2023-39945?
Yes, Debian Linux 11.0 and 12.0 are affected by CVE-2023-39945.