CVE-2023-39946: Heap overflow in push_back_helper due to a CDR message
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PIDPROPERTYLIST parameter that contains a CDR string with length larger than the size of actual content. In eprosima::fastdds::dds::ParameterPropertyListt::pushbackhelper, memcpy is called to first copy the octet'ized length and then to copy the data into properties.data. At the second memcpy, both data and size can be controlled by anyone that sends the CDR string to the discovery multicast port. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39946?
CVE-2023-39946 is a vulnerability in eprosima Fast DDS that allows for a heap overflow by providing a PID_PROPERTY_LIST parameter with a CDR string of larger length.
How does CVE-2023-39946 affect eprosima Fast DDS?
CVE-2023-39946 affects eprosima Fast DDS versions 2.6.0 to 2.6.6, 2.9.0 to 2.9.2, 2.10.0 to 2.10.2, and 2.11.0.
What is the severity of CVE-2023-39946?
CVE-2023-39946 has a severity rating of 7.5, which is considered high.
How can I fix CVE-2023-39946?
To fix CVE-2023-39946, upgrade to eprosima Fast DDS versions 2.6.7, 2.9.3, 2.10.3, or 2.11.1.
Where can I find more information about CVE-2023-39946?
You can find more information about CVE-2023-39946 in the eprosima Fast DDS GitHub repository and the Debian Security Advisory.